
hazel-cve-2026-43499
Firmware-specific temporary root exploit for Toshiba/Amazon Fire TV (hazel) using CVE-2026-43499. Implements ARM32 futex-PI UAF, kernel address leak,…

Firmware-specific temporary root exploit for Toshiba/Amazon Fire TV (hazel) using CVE-2026-43499. Implements ARM32 futex-PI UAF, kernel address leak,…

Ghidra extension for PC firmware reverse engineering, providing loaders for PCI option ROMs, Intel Flash Descriptor, coreboot CBFS, and UEFI firmware…

Ghidra plugin that automates UEFI firmware analysis by identifying known GUIDs, protocols, SMI handlers, and interrupt functions, with headless…

IDA plugin to enhance (U)EFI binary reversing with batch analysis, GUID database, and service usage statistics for firmware security research.

IDA plugin for extending UEFI reverse engineering capabilities

Some scripts for IDA Pro to assist with reverse engineering EFI binaries

rt26cx21x64.sys exploit (Realtek PCIe GbE/2.5GbE/5GbE family)

Proof-of-concept demonstrating hardcoded root credentials (admin/system) in Tenda HG21 XPON modem firmware, enabling unauthorized root access via…

Security research on a consumer IP camera built on the Fullhan FH8626V100 SoC (model AJL30PG0803).

Simulates a Bluetooth keyboard to exploit CVE-2023-45866, injecting keystrokes via DuckyScript on vulnerable Android, iOS, macOS, and Linux devices…

Work-in-progress PoC for CVE-2025-27840, an ESP32 Bluetooth vulnerability involving undocumented HCI commands enabling memory access and device…

Firmware repository for CatSniffer, a multi-protocol IoT security research board supporting BLE, Zigbee, Sub-1 GHz, and more, with version-specific…

Proof-of-concept for NVIDIA GreenSection memory corruption 0day, demonstrating out-of-bounds write via shared memory section, enabling cross-user…

Your ONVIF and RTSP camera companion for discovering and hacking real-world security cameras 🎥

Proof-of-concept demonstrating hardcoded root credentials (admin/system) in Tenda HG21 XPON modem firmware, enabling unauthorized root access via…

Research tools for MouseJack vulnerabilities in nRF24L01 wireless devices, including device discovery, packet sniffing, network mapping, and firmware…

LoRaWAN session cracker - A PoC for exploiting weak or shared Application Keys

Set your radio to 148.500 MHz, select FM, USB, or CW mode, and set the squelch to 0 or 1. Then, extend your radio's antenna toward the monitor's HDMI…