
-CVE-2024-45352
Technical PoC and analysis of CVE-2024-45352, a critical unauthenticated RCE in Xiaomi Smarthome via improper API input handling, with exploit…

Technical PoC and analysis of CVE-2024-45352, a critical unauthenticated RCE in Xiaomi Smarthome via improper API input handling, with exploit…

Vatilon-based IP camera firmware allows authentication bypass and plaintext credential exposure via web.cgi API requests.

Proof-of-concept exploit for CVE-2023-49965: Cross-Site Scripting (XSS) in Starlink Router Gen 2 captive portal, enabling CSRF-based control of…

Exploit for CVE-2017-12943, a D-Link DIR-600 router authentication bypass, allowing unauthorized access without a password.

Proof-of-concept exploits for IoT device vulnerabilities, including TOTOLINK login bypass CVEs, with detailed technical analysis and reproduction…

This script exploits a vulnerability (IoF) in the TPLink WR840N router, using a field for injecting code in the module DNS.

TP-Link Archer BE800 V1 — Parental Control LAN RCE

Python exploit for D-Link routers using Service.cgi command injection to provide a limited BusyBox shell on affected DIR-110/412/600/610/615/645/815…