
CVE-2026-3227-TP-Link-authenticated-RCE
Proof-of-concept for authenticated OS command injection in TP-Link router firmware. Includes decryption, QEMU-based encryption hook, and 15-character…

Proof-of-concept for authenticated OS command injection in TP-Link router firmware. Includes decryption, QEMU-based encryption hook, and 15-character…

Proof-of-concept exploits for TP-Link routers, including remote command execution and authentication bypass vulnerabilities.

BlackVue DR750 CVE CVE-2023-27746 CVE-2023-27747 CVE-2023-27748

Analyzing and Reproducing the Command Injection Vulnerability (CVE-2023-0861) in NetModule Routers

Public writeup, PoC, and emulation materials for CVE-2026-6837 affecting Zyxel export-cgi PKCS#12 export handling.

Proof-of-concept exploit for CVE-2019-10915 targeting an authentication bypass in Siemens TIA Administrator, enabling remote command execution via…

Python script to exploit CVE-2020-35391 on Tenda F3 V3/V4 routers, enabling unauthorized download of configuration, flash, and syslog files.

Static analysis of D-Link router firmware revealing buffer overflow vulnerabilities in HTTP handling, including CVE-2017-14948, with disassembly and…

Proof-of-concept of vulnerability found in Totolink A720R router

PoC exploit and tooling for CVE-2021-26258, including a custom storage file packer/unpacker and a MITM web server to deliver malicious updates to…

Post-authentication command injection exploit for Wavlink AC1200 routers. Leverages improper input sanitization in adm.cgi to execute arbitrary shell…

Detailed analysis of CVE-2019-12489 command injection in Fastgate modem/router firmware, including firmware extraction, reverse engineering with…

This repo has a blog post about my analysis for CVE-2018-19987 an authenticated OS command injection affecting multiple D-Link routers

Cookie-based authentication vulnerability on Tk-Rt-Wr135G

Proof-of-concept and analysis for CVE-2021-4045, a command injection RCE in the TP-Link Tapo C200 IP camera's uhttpd affecting firmware prior to…

Proof-of-concept exploit for CVE-2020-12124 targeting Wavlink AC1200 router, demonstrating unauthenticated command injection and stack buffer…

Proof-of-concept exploit for CVE-2021-3166 targeting ASUS DSL-N14U routers via malicious firmware upload, triggering a denial-of-service condition.