
draytek-arsenal
Reverse Engineering and Observability toolkit for Draytek firewalls

Reverse Engineering and Observability toolkit for Draytek firewalls

Active fingerprinting tool that identifies 16 embedded TCP/IP stacks on network devices using ICMP, TCP, HTTP, SSH, and FTP probing techniques for…

Build repo from Universal Wifi pineapple hardware cloner

Python script to exploit CVE-2020-35391 on Tenda F3 V3/V4 routers, enabling unauthorized download of configuration, flash, and syslog files.

nextpnr portable FPGA place and route tool

This repo contains instructions to reproduce CVE-2025-13425: Null Pointer dereference / Array over-indexing vulnerability that I found in Google's…

A tool to manipulate Schneider Electric PLC archive files

C library providing a portable API for acquiring signals from logic analyzers, oscilloscopes, multimeters, and other test instruments, with…

The unofficial Official FirmWare, a complete latest PSP firmware reverse engineering project

The firmware engineering home of the Circuit Crafters first electronic badge project.

The firmware board support package home of the Circuit Crafters first electronic badge project.

Defensive vulnerability-research project comparing vulnerable and patched Grandstream GXP1600 firmware for CVE-2026-2329, using SquashFS extraction,…

In the Pixel cellular firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with…

Linux operating system for embedded devices with writable filesystem, package management, and build framework. Enables custom firmware creation for…

Cross-platform library to parse, modify, and abstract ELF, PE, and MachO executable formats. Supports C++, Python, and Rust APIs with disassembler,…

Breathe fresh life into your bricked Nest, now with 100% less evil!

First open source and publicly available System Management Mode backdoor for UEFI based platforms. Good as general purpose playground for various SMM…