
CVE-2017-16778-Intercom-DTMF-Injection
A coordinated disclosure and security advisory on Fermax Intercom DTML Injection vulneraiblity. Special thanks to Fermax International for prompt…

A coordinated disclosure and security advisory on Fermax Intercom DTML Injection vulneraiblity. Special thanks to Fermax International for prompt…

Collection of "modchip" designs for launching payloads via the Tegra RCM bug (CVE-2018-6242)

D-Link DSL-3782 Code Execution (Proof of Concept)

CVE-2020-36109 PoC causing DoS

Boots a custom Linux kernel on rooted LG webOS TVs via kexec, with reverse-engineered SoC watchdog support, framebuffer payloads, and an initramfs…

Owning a tablet Amazon kept shutting down — CVE-2022-38181 write-up, four AI models, and a blog

CVE-2025-70962 PoC

Security advisories for CVE-2021-43716/43717/43718 (Epson EH-TW5350)

PoCs and evidence for two NVIDIA Linux GPU driver findings closed by the vendor as expected/intended behavior: cross-UID GPU process telemetry via…

Or how I turn off my TV via a cronjob

eWeLinkESPT is a tool that automatically decodes and decrypts the WiFi network credentials transmitted to a supported ESP-based IoT device by the…

Proof-of-concept exploit for authenticated remote code execution (CVE-2021-44827) targeting TP-Link Archer C20i routers. Provides post-exploitation…

Disclosure of Accfly camera vulnerabilities: CVE-2020-25782, CVE-2020-25783, CVE-2020-25784, CVE-2020-25785.

POC for CVE-2025-29384

CVE-2025-1242: Hardcoded iothubowner Connection String — Gardyn Home Kit (ICSA-26-055-03)

Patch your D-Link device affected by CVE-2024-3272

Documents CP PLUS EZ-P21 IP camera CVEs: arbitrary code execution via debug feature and improper authentication of HTTP endpoints, with responsible…

Proof-of-concept exploit suite for U-Boot bootloader vulnerabilities, including insecure update mechanisms, hardcoded credentials, debugging…