
reverse-skill
AI-powered skill router pack for reverse engineering, penetration testing, and security research. Routes AI agents to correct methodologies and…

AI-powered skill router pack for reverse engineering, penetration testing, and security research. Routes AI agents to correct methodologies and…

Original research and PoC for a pre-auth stack buffer overflow via unbounded sscanf scanset in the Netis NC63 ipFilterList handler

PoC toolkit that unpacks router firmware, decrypts device secrets, forges JWT tokens, and exploits CVE-2026-71960/71961 to take over Cudy WR3000 mesh…

DoS against Belkin smart plugs via crafted firmware injection

Proof-of-concept exploit for CVE-2021-3166 targeting ASUS DSL-N14U routers via malicious firmware upload, triggering a denial-of-service condition.

The wolfSSL library is a small, fast, portable implementation of TLS/SSL for embedded devices to the cloud. wolfSSL supports up to TLS 1.3 and DTLS…

Cross-platform library to parse, modify, and abstract ELF, PE, and MachO executable formats. Supports C++, Python, and Rust APIs with disassembler,…

A curated list of public TEE resources for learning how to reverse-engineer and achieve trusted code execution on ARM devices

BootStomp: a bootloader vulnerability finder

Unlock the Meta Quest 1 bootloader and gain root access using GhostLock + CVE-2021-1931.

Multi OS Support: Version for MacOS/Linux and Windows, Fully translated to English

Unlock Bootloader for Itel S23 (S665L) / Unisoc T606 using CVE-2022-38694

DoS against Belkin smart plugs via crafted firmware injection

The reverse-engineering expert agent: plans its own analysis path, derives every fact from raw evidence, and converges under mechanical verification…

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

Demonstrates CVE-2026-8888, an unsigned printer firmware update over HTTP, including a malicious update server and vulnerable printer emulator for…

Custom C exploit for CVE-2020-8423 targeting MIPS routers, featuring hooked open() syscall and tailored for Linux kernel 2.6.31.