
mtkclient
Mediatek Flash and Repair Utility

Mediatek Flash and Repair Utility

CVE-2026-11499

Reproducible crash proof-of-concept for CVE-2015-3456 (VENOM) targeting QEMU's virtual floppy disk controller. Demonstrates guest-controlled writes…

POC for CVE-2025-24132 (AirBourne). Currently just triggers the overflow and causes a crash

Analysis and PoC for CVE-2025-14174 - ANGLE Metal OOB write (iOS Safari, macOS Chrome)

PoC and vulnerability report for CVE-2025-47827.

Documentation of CVE-2025-51643: physical SPI flash extraction on Meitrack T366G-L GPS tracker enabling firmware dump, plaintext credential…

Platform security assessment tool for dumping and analyzing UEFI/SMM registers, PCI config space, physical memory, SPI flash, and S3 bootscripts with…

CVE-2024-44815

Proof-of-concept exploit for a buffer overflow vulnerability in H3C Magic B1STW router's SetAPInfoById function, causing web service crash and…

ELAN Miniport touchpad Windows driver before 24.21.51.2, as used in PC hardware from multiple manufacturers, allows local users to cause a system…

Firmware and research tools for Nordic Semiconductor nRF24LU1+ based USB dongles and breakout boards.

asadbg is a framework of tools to aid in automating live debugging of Cisco ASA devices

SPI flash read MitM attack PoC

Super UEFIinSecureBoot Disk: Boot any OS or .efi file without disabling UEFI Secure Boot

Pixel bootlaoder exploit for reading flash storage

A bunch of routers firmware images. Principally those that are not available and they do need to be extracted via JTAG, UART, desoldering flash or…