
pwndbg
Exploit Development and Reverse Engineering with GDB & LLDB Made Easy

Exploit Development and Reverse Engineering with GDB & LLDB Made Easy

Open-source simulation framework for developing, testing, and debugging unmodified software for multi-node embedded and IoT systems, supporting ARM,…

ESP32DIV is a multi-purpose wireless offensive and defensive toolkit powered by an ESP32

Backports of three published f_hid fixes (incl. CVE-2026-31721, CVE-2026-31606) to an EOL Linux 4.14.190 Android vendor kernel, with on-device…

Chase H.Q. for ZX Spectrum — reverse-engineered and reconstructed in portable C

PoCs and evidence for two NVIDIA Linux GPU driver findings closed by the vendor as expected/intended behavior: cross-UID GPU process telemetry via…

Security advisories for CVE-2021-43716/43717/43718 (Epson EH-TW5350)

Run Radmin VPN on Linux via Wine — custom driver, TAP bridge, zero packet loss

Simulated Zigbee Light Link (ZLL) factory reset exploit for CVE-2026-21006, demonstrating unauthenticated TouchLink command injection that wipes…

Reverse-engineered BLE protocol for the CMF Watch Pro 2, documenting GATT layout, AES-128-CBC encrypted command frames, authentication handshake, and…

No-dongle, no-root Bluetooth security assessment tool for wireless earbuds affected by the Airoha SDK vulnerability chain (CVE-2025-20700/20701/20702)

Firmware repository for CatSniffer, a multi-protocol IoT security research board supporting BLE, Zigbee, Sub-1 GHz, and more, with version-specific…

rt26cx21x64.sys exploit (Realtek PCIe GbE/2.5GbE/5GbE family)

Ghidra processor description module for NEC/Renesas v810 and v830 families

Interactive wizard to flash EFF's Rayhunter on Orbic RC400L — auto-detects OS

PoC exploit chain for TP-Link Tapo C260 camera — CVE-2026-0651/0652/0653. Research by @spaceraccoon.

Documenting Osmo Mobile BLE protocol

A denial-of-service vulnerability in the AuntyFey BLE smart padlock allows unauthenticated connection floods to lock out legitimate users. …