
nexmon
The C-based Firmware Patching Framework for Broadcom/Cypress WiFi Chips that enables Monitor Mode, Frame Injection and much more

The C-based Firmware Patching Framework for Broadcom/Cypress WiFi Chips that enables Monitor Mode, Frame Injection and much more

Presented at Recon Montreal 2018

CVE-2024-44815

Tenda Technology Co., Ltd NVR_4H: CH3 v2.1.V27.5.58.6 was discovered to contain a hardcoded cryptographic key.

Python script to exploit CVE-2020-35391 on Tenda F3 V3/V4 routers, enabling unauthorized download of configuration, flash, and syslog files.

This is a suite of tools/PoCs/exploits for cameras using the iCSee application. And yes - it can run NES games!

Cookie-based authentication vulnerability on Tk-Rt-Wr135G

Technical disclosure of CVE-2024-33676: weak authentication on Enel X JuiceBox EV chargers enabling PII extraction, settings manipulation, and OS…

TROMMEL: Sift Through Embedded Device Files to Identify Potential Vulnerable Indicators

Python PoC for CVE-2026-100740, an L2TP Host Name AVP out-of-bounds write in D-Link DIR-895L A1_102b07 tunnel_set_params. Fingerprints the device and…

Research tools for MouseJack vulnerabilities in nRF24L01 wireless devices, including device discovery, packet sniffing, network mapping, and firmware…

Quarkslab conference talks

IoT firmware identification and extraction

Live, system-wide USB transfer sniffer in eBPF — decodes USB traffic inline (control SETUP, SCSI, HID) from two universal URB hooks. No usbmon, no…

Python dumper/explorer for MCD Runtime Projects used by ODIS

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Security issue in the hypervisor firmware of some older Qualcomm chipsets

Talk to your Intel Management Engine directly — zero-dependency Python tool. Finds memory leaks, partition manifest, live MKHI probing. First public…