
IoTGoat
Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

Exploit for command injection vulnerability found in uhttpd binary from TP-Link Tapo c200 IP camera

Proof of Concept for CVE-2023-22906

[CVE-2018-6479] Netwave IP Camera server vulnerable to Denial of Service via one single huge POST request.

CVE-2023-49965 | SpaceX / Starlink Router Gen 2 XSS

Dahua CVE-2026-29115

Dahua CVE-2026-29116


DoS against Belkin smart plugs via crafted firmware injection

Technical report about a critical vulnerability in Xiaomi (CVE-2024-45352)

This repo describes a vulnerability affecting the QR code based pairing process of the eWeLink IoT devices (CVE-2020-12702).

Flexwatch-CVE



Vatilon-based IP camera firmware allows authentication bypass and plaintext credential exposure via web.cgi API requests.

CVE-2026-38426 — strcpy() Stack Buffer Overflow in Tasmota fetch_jpg() boundary[40] (Tasmota <= 15.3.0.3)

POC for CVE-2025-29384

This script exploits a vulnerability (IoF) in the TPLink WR840N router, using a field for injecting code in the module DNS.