
CVE-2025-47827
PoC and vulnerability report for CVE-2025-47827.

PoC and vulnerability report for CVE-2025-47827.

Technical writeup for CVE-2024-20154

Reverse engineering of the engine powering the PriPara games on arcade.


Firmware security analysis of BD Alaris 8015 infusion pump (CVE-2016-9355). Identified 6 compound vulnerabilities including plaintext Wi-Fi…



Proof-of-concept exploit for CVE-2026-1668.

This repo has a blog post about my analysis for CVE-2018-19987 an authenticated OS command injection affecting multiple D-Link routers

对NETIS WF2409E路由器进行的一次完整硬件安全分析研究。通过对设备进行拆解分析、调试接口识别、固件提取等工作,记录了硬件分析的全过程、漏洞细节以及相应的安全建议,希望能帮助提高物联网设备的安全性。

Drone HASAKEE FPV video app for Android

Simplifies D-Link DCS-932L firmware emulation with pre-patched components and includes a Proof-of-Concept exploit for CVE-2024-37606."

Lets have fun by digging into a Zyxel router firmware and MIPS Arch

Lets have fun by digging into a Zyxel router firmware and MIPS Arch

Hardware Hacking Cheatsheet

Writeup for Tenda AC15 router firmware rehosting and remote command execution (CVE-2020-10987) exploit replication.

CVE-2025-50777: Root Access and Plaintext Credential Exposure in AZIOT Smart CCTV

An implementation of a proof-of-concept for CVE-2020-12124