
Awesome-Android-Reverse-Engineering
A curated list of awesome Android Reverse Engineering training, resources, and tools.

A curated list of awesome Android Reverse Engineering training, resources, and tools.

The first analysis framework for CPU microcode

Proof-of-concept for authenticated OS command injection in TP-Link router firmware. Includes decryption, QEMU-based encryption hook, and 15-character…

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

BlackVue DR750 CVE CVE-2023-27746 CVE-2023-27747 CVE-2023-27748

Proof-of-concept exploits for TP-Link routers, including remote command execution and authentication bypass vulnerabilities.

Analyzing and Reproducing the Command Injection Vulnerability (CVE-2023-0861) in NetModule Routers

Python script to exploit CVE-2020-35391 on Tenda F3 V3/V4 routers, enabling unauthorized download of configuration, flash, and syslog files.

CVE-2017-14948 for D-Link 880 Firmware

Proof-of-concept of vulnerability found in Totolink A720R router

Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while…


This repo has a blog post about my analysis for CVE-2018-19987 an authenticated OS command injection affecting multiple D-Link routers

Cookie-based authentication vulnerability on Tk-Rt-Wr135G

CVE-2021-4045 CVE-2021-4045 is a Command Injection vulnerability that allows Remote Code Execution in the TP-Link Tapo c200 IP camera. It affects all…

Proof-of-concept exploit for CVE-2020-12124 targeting Wavlink AC1200 router, demonstrating unauthenticated command injection and stack buffer…

Proof-of-concept exploit for CVE-2021-3166 targeting ASUS DSL-N14U routers via malicious firmware upload, triggering a denial-of-service condition.

PoC exploit chain for TP-Link Tapo C260 camera — CVE-2026-0651/0652/0653. Research by @spaceraccoon.