
Firmware-analysis
Rediscovered CVE-2020-25279, a critical vulnerability in the Shannon baseband used in Samsung Exynos chipsets

Rediscovered CVE-2020-25279, a critical vulnerability in the Shannon baseband used in Samsung Exynos chipsets

Technical writeup for CVE-2024-20154

Reverse engineering of the engine powering the PriPara games on arcade.

This is a collection of Unisoc BootROMs dumped from various Unisoc chipsets via CVE-2022-38694

UNISOC BootROM/FDL flasher for macOS: patched spd_dump with CVE-2022-38694 exec_addr2, protocol reference, partition rules, backup verification…

From Solder to Shell: Full Hardware Exploitation of the Linksys WRT54GL Router (CVE-2022-43973)

CVE-2017-14948 for D-Link 880 Firmware

Proof-of-concept of vulnerability found in Totolink A720R router

CVE-2023-31070 Broadcom BCM47xx SDK slab-out-of-bounds write PoC

This repo has a blog post about my analysis for CVE-2018-19987 an authenticated OS command injection affecting multiple D-Link routers

Demonstrates a local access control bypass in AMI Aptio 5 NvLock module, allowing modification of NVRAM variables including administrator password,…

对NETIS WF2409E路由器进行的一次完整硬件安全分析研究。通过对设备进行拆解分析、调试接口识别、固件提取等工作,记录了硬件分析的全过程、漏洞细节以及相应的安全建议,希望能帮助提高物联网设备的安全性。

解决网络安全漏洞

DoS against Belkin smart plugs via crafted firmware injection

Drone HASAKEE FPV video app for Android

Implements the mitigation for CVE-2025-54505 as described by AMD-SB-7053

DoS against Belkin smart plugs via crafted firmware injection

This repo contains instructions to reproduce CVE-2025-13425: Null Pointer dereference / Array over-indexing vulnerability that I found in Google's…