
trommel
Static analysis tool that sifts through embedded device firmware to identify vulnerable indicators including SSH/SSL keys, IPs, URLs, shell scripts,…

Printer Exploitation Toolkit - The tool that made dumpster diving obsolete.

ESP8266-based hardware tool for logging and replaying Wiegand interface data from access control systems. Captures HID card credentials, supports PIN…

Talk to your Intel Management Engine directly — zero-dependency Python tool. Finds memory leaks, partition manifest, live MKHI probing. First public…

Python script to exploit CVE-2020-35391 on Tenda F3 V3/V4 routers, enabling unauthorized download of configuration, flash, and syslog files.

High-performance network scanner for large-scale IP and port scanning with service identification, embedded device detection, and vulnerability…

Footprinting and fingerprinting tool for robotic systems, including ROS, ROS2, SROS, and industrial routers. Scans networks, detects nodes, topics,…

I2C-based HDMI DDC traffic sniffer for recovering HDCP cryptographic keys and decoding EDID, MCCS data using a Bus Pirate and breakout cable.

Network-based scanner that identifies devices running Interpeak IPnet TCP/IP stack to detect URGENT/11 vulnerabilities using TCP and ICMP…

This project demonstrates the publicly disclosed CVE-2018-9995 vulnerability found in multiple embedded DVR devices.

The C-based Firmware Patching Framework for Broadcom/Cypress WiFi Chips that enables Monitor Mode, Frame Injection and much more

This firmware is an alternative to the EvilCrowRF default firmware. Module: CC1101 - Compatible Flipper Zero file.

Proof-of-concept exploit and vulnerability disclosure for HiSilicon hi3520d DVR/NVR devices. Demonstrates RCE via web interface, backdoor…

Documentation and reproduction steps for CVE-2022-24693: hardcoded credentials in Baicells Nova436Q and Neutrino 430 firmware, enabling remote SSH…

CVE-2021-21735 write-up: ZTE ZXHN H168N V3.5 wizard-page information leak, firmware routing flaw, and the path from exposed PPPoE/WLAN data to full…

Disclosure of CVE-2025-45466 detailing hardcoded plaintext SSH credentials in Unitree Go1 robotic dog firmware, enabling remote code execution,…

Proof-of-concept exploit for CVE-2025-45467, demonstrating remote code execution on Unitree Go1 robotic dogs via insecure MD5-based firmware…

Exploit vulnerable Brother printers via CVE-2017-7588, collect data, and develop custom firmware implants for attack simulation.