
raspberrypi-setup
Ansible playbook for rapid Raspberry Pi setup with modular roles for wireless security testing, RFID/NFC tools, SDR, Docker, Tor proxy, and standard…

Ansible playbook for rapid Raspberry Pi setup with modular roles for wireless security testing, RFID/NFC tools, SDR, Docker, Tor proxy, and standard…

Custom firmware for Flipper Zero enabling Sub-GHz radio, NFC/RFID emulation, infrared, and BadUSB attack features for hardware security testing.

Open-source GPS tracking system supporting 200+ protocols and 2000+ device models. Provides real-time tracking, geofencing, driver monitoring, and…

Vatilon-based IP camera firmwares issue Session-Id tokens without verifying credentials, allowing attackers to obtain sessions and retrieve plaintext…

Proof-of-concept exploit for CVE-2025-29384, a critical stack-based buffer overflow in Tenda AC9 routers. Includes Python and Metasploit modules for…

Proof-of-concept exploit for a buffer overflow vulnerability (CVE-2024-44596) in Netis N5VN AC1200 routers, causing a denial of service by crashing…

Proof-of-concept exploit demonstrating UDS authentication bypass via challenge-response replay on automotive ECUs, with Python CAN-UDS simulator.

Proof-of-concept exploits for CVE-2025-52688: unauthenticated command injection and arbitrary file read vulnerabilities in Alcatel AP13161 enterprise…

This repo describes a vulnerability affecting the QR code based pairing process of the eWeLink IoT devices (CVE-2020-12702).

Python exploit for TP-Link TL-WR840N RCE (CVE-2022-25064) via crafted IPv6 address payload in the router's CGI interface, enabling remote command…

Proof-of-concept exploit for authentication bypass via capture-replay in Dingtian DT-R002 relay, allowing unauthorized control of relays through HTTP…

[CVE-2018-6479] Netwave IP Camera server vulnerable to Denial of Service via one single huge POST request.

TypeScript PoC for CVE-2024-54887 (TP-Link TL-WR940N authenticated RCE)

Proof-of-concept code (Bash and Python) for CVE-2025-65856 where ONVIF implementation in in Xiongmai XM530 IP cameras allows for unauthenticated …

Public disclosure of Tecnovision DlxSpot Player 4 vulnerabilities: hardcoded SSH credentials, SQL injection, and arbitrary file upload to remote code…

Exploits CVE-2022-30075 to achieve authenticated remote code execution on TP-Link Archer AX50 routers, including configuration decryption, command…

Python exploit for CVE-2020-35713 that changes the admin password on Belkin LINKSYS RE6500 devices via shell metacharacters in the goform/setSysAdm…
