
ThrottleStopPoC
CVE-2025-7771: Arbitrary physical memory and I/O port read/write via ThrottleStop driver

CVE-2025-7771: Arbitrary physical memory and I/O port read/write via ThrottleStop driver

Intel Management Engine JTAG Proof of Concept - 2022 Instructions

Reverse-engineered Logi Options+ agent IPC protocol. Switch Logitech multi-host devices programmatically via Unix socket (macOS) or named pipe…

A coordinated disclosure and security advisory on Fermax Intercom DTML Injection vulneraiblity. Special thanks to Fermax International for prompt…

Collection of "modchip" designs for launching payloads via the Tegra RCM bug (CVE-2018-6242)

AuthBypass & Auto Backdooring Devices

Google Tensor Cracks

CVE-2022-38694 Hardened Exploit - RP2350 USB Host Auto Flasher for Unisoc devices

Library for WCH CH56x-based boards with tested USB3/USB2/HSPI/SerDes drivers, logging and deferred interrupts

Proof-of-concept exploits for three vulnerabilities in Crucial MX500 SSD firmware update mechanism, enabling buffer overflows and potential code…

Boots a custom Linux kernel on rooted LG webOS TVs via kexec, with reverse-engineered SoC watchdog support, framebuffer payloads, and an initramfs…

Print trace messages over a Silicon Labs C2 debugger connection

From UART to Root: Breaking Into the Xiaomi C200 via U-Boot

BLE-based tool that automatically discovers and exploits Shining LED Masks by uploading a custom image without user interaction, proving security…

Firmware extractor for CH55x microprocessors

Make the miko robot a free one

From a bare PCB to root: hardware-hacking a ZyXEL P-870HN (BCM6368) over UART — CVE-2025-0890 + CVE-2024-40891, on my own hardware.

Stack buffer overflow PoC for a hardware wallet USB descriptor parser (CVE-2026-22013), showing return-address overwrite and code execution via…