
powerg-tools
Tools for reverse engineering and interacting with the PowerG radio protocol

Tools for reverse engineering and interacting with the PowerG radio protocol

Reverse Engineering of the Shining App Mask

PoC repository for CVE-2020-6861: Ledger Monero App Spend key Extraction

Exploits for GL.iNet CVE-2023-46454, CVE-2023-46455 and CVE-2023-46456

Documentation and reproduction steps for CVE-2022-24693: hardcoded credentials in Baicells Nova436Q and Neutrino 430 firmware, enabling remote SSH…

A buffer overflow in the component nfc_device_load_mifare_ul_data of Flipper Devices Inc., Flipper Zero before v0.65.2 allows attackers to cause a…

Payload injection tool for Nintendo Switch consoles vulnerable to CVE-2018-6242 ("Fusée Gelée")

Extracts hardware random keys from NEC Aterm router firmware images and QR codes to generate valid passwords for gaining shell access.

Technical advisory and proof-of-concept for a stack-based buffer overflow (CWE-121) in the NXP moal.ko Wi-Fi kernel driver, enabling local kernel…

The firmware board support package home of the Circuit Crafters first electronic badge project.

Stack buffer overflow PoC for a hardware wallet USB descriptor parser (CVE-2026-22013), showing return-address overwrite and code execution via…

POCs for CVE-2017-13672 (OOB read in VGA Cirrus QEMU driver, causing DoS)

An active cyber defense & honeypot system for OpenWrt routers running from a USB drive.

Replays captured CAN bus frames to demonstrate CVE-2026-21014, showing how missing authentication and freshness checks enable unauthorized automotive…

Proof-of-concept exploit for CVE-2026-85769, a heap out-of-bounds read in libtpms TPM 2.0 state deserialization, demonstrating denial of service via…


Demonstrates a local access control bypass in AMI Aptio 5 NvLock module, allowing modification of NVRAM variables including administrator password,…

RMASmoke main repo. CVE-2025-1122