
st25tb_kiemul
ST25TB / SRx NFC Emulator / Initiator based on TI TRF7970A with MSP430

ST25TB / SRx NFC Emulator / Initiator based on TI TRF7970A with MSP430

Reverse engineering the TI AM3358 boot ROM

Exploit writeups I've authored

A game modding utility that makes injecting C/C++ code easier.

Cisco RV110w UPnP stack overflow

A yet non-offical neighbor for the GreatFet One targeting the 433/868/915MHz bands

SPI flash read MitM attack PoC

Reverse-engineered Logi Options+ agent IPC protocol. Switch Logitech multi-host devices programmatically via Unix socket (macOS) or named pipe…

Configure your Pi Zero 2W to be a BadUSB

Intel Management Engine JTAG Proof of Concept - 2022 Instructions

Collection of "modchip" designs for launching payloads via the Tegra RCM bug (CVE-2018-6242)

AuthBypass & Auto Backdooring Devices

No-open firmware exploit for the Wyze WLPA19CV2 color bulb

Exploit for CVE-2026-40003, an arbitrary memory write vulnerability in ZXIC/Sanechips ZX297520V3 SoC BootROM, enabling code execution via USB…

A tool for performing MouseJack keystrokes injection attack.

*Proof of concept* Attacks a Windows machine running Windows 7 or later, creating a persistent Backdoor.

Firmware extractor for CH55x microprocessors

From a bare PCB to root: hardware-hacking a ZyXEL P-870HN (BCM6368) over UART — CVE-2025-0890 + CVE-2024-40891, on my own hardware.