
CVE-2025-63667
Vatilon-based IP camera firmwares issue Session-Id tokens without verifying credentials, allowing attackers to obtain sessions and retrieve plaintext…

Vatilon-based IP camera firmwares issue Session-Id tokens without verifying credentials, allowing attackers to obtain sessions and retrieve plaintext…

Documentation of CVE-2025-51643: physical SPI flash extraction on Meitrack T366G-L GPS tracker enabling firmware dump, plaintext credential…

CVE-2026-43499 exploit with OnePlus Ace3 support

Vatilon-based IP camera firmware allows authentication bypass and plaintext credential exposure via web.cgi API requests.

This vulnerability impacts device availability and reliable operation of Atomberg Erica Smart Fan(Firmware Version 1.0.36). The issue arises due to a…

Bluetooth Classic HID injection exploit for CVE-2023-45866, enabling unauthenticated keystroke injection against vulnerable BlueZ-based Linux systems.

Proof-of-concept exploit for CVE-2018-20162: sandbox escape in Digi TransPort LR54 LTE router via SIGINT handling flaw, yielding root shell access.

Implementation of Key Negotiation Of Bluetooth (KNOB) attacks targeting Bluetooth BR/EDR and BLE, exploiting CVE-2019-9506 for security research and…

Exploit code for CVE-2023-28810

Proof-of-concept exploit for CVE-2024-27619 causing denial of service on D-Link DIR-3040/3060 routers via FTP memory exhaustion without…

Proof-of-concept exploits for IoT device vulnerabilities, including TOTOLINK login bypass CVEs, with detailed technical analysis and reproduction…

Proof-of-concept exploit for a buffer overflow vulnerability in Tenda AC8v4 router firmware (V16.03.34.09) via the SetNetControlList endpoint,…

Proof-of-concept exploit for a buffer overflow vulnerability (CVE-2024-44596) in Netis N5VN AC1200 routers, causing a denial of service by crashing…

Telnet default credentials can lead to information disclosure and denial-of-service (DoS) attacks.

Proof-of-concept exploit for CVE-2023-25234, a stack overflow vulnerability in Tenda AC6 routers, enabling remote code execution via crafted HTTP…

PoCs and evidence for two NVIDIA Linux GPU driver findings closed by the vendor as expected/intended behavior: cross-UID GPU process telemetry via…

Local root exploit for CVE-2025-21479 (Adreno KGSL) on iQOO Neo8 (SM8475) - physical memory r/w, disables SELinux, spawns root shell

Low-cost open-source software-defined radio platform with hardware designs and firmware for RF transmission, reception, and signal analysis from 1…