
CVE-2026-9254
TP-Link Archer BE800 V1 — Parental Control LAN RCE

TP-Link Archer BE800 V1 — Parental Control LAN RCE

Custom firmware for Flipper Zero enabling Sub-GHz radio, NFC/RFID emulation, infrared, and BadUSB attack features for hardware security testing.

Proof-of-concept exploit demonstrating UDS authentication bypass via challenge-response replay on automotive ECUs, with Python CAN-UDS simulator.

Public disclosure of Tecnovision DlxSpot Player 4 vulnerabilities: hardcoded SSH credentials, SQL injection, and arbitrary file upload to remote code…

Open-source GPS tracking system supporting 200+ protocols and 2000+ device models. Provides real-time tracking, geofencing, driver monitoring, and…

Proof-of-concept exploit for a buffer overflow vulnerability (CVE-2024-44596) in Netis N5VN AC1200 routers, causing a denial of service by crashing…

Proof-of-concept exploit for CVE-2023-49965: Cross-Site Scripting (XSS) in Starlink Router Gen 2 captive portal, enabling CSRF-based control of…

Proof-of-concept code (Bash and Python) for CVE-2025-65856 where ONVIF implementation in in Xiongmai XM530 IP cameras allows for unauthenticated …

This repo describes a vulnerability affecting the QR code based pairing process of the eWeLink IoT devices (CVE-2020-12702).

Proof-of-concept exploit for CVE-2025-29384, a critical stack-based buffer overflow in Tenda AC9 routers. Includes Python and Metasploit modules for…

TypeScript PoC for CVE-2024-54887 (TP-Link TL-WR940N authenticated RCE)

Technical PoC and analysis of CVE-2024-45352, a critical unauthenticated RCE in Xiaomi Smarthome via improper API input handling, with exploit…

Python exploit for TP-Link TL-WR840N RCE (CVE-2022-25064) via crafted IPv6 address payload in the router's CGI interface, enabling remote command…


Proof-of-concept exploits for CVE-2025-52688: unauthenticated command injection and arbitrary file read vulnerabilities in Alcatel AP13161 enterprise…

This script exploits a vulnerability (IoF) in the TPLink WR840N router, using a field for injecting code in the module DNS.

[CVE-2018-6479] Netwave IP Camera server vulnerable to Denial of Service via one single huge POST request.

Proof-of-concept exploits for IoT device vulnerabilities, including TOTOLINK login bypass CVEs, with detailed technical analysis and reproduction…