
Xiaomi-C200-Firmware-Analysis
From UART to Root: Breaking Into the Xiaomi C200 via U-Boot

From UART to Root: Breaking Into the Xiaomi C200 via U-Boot

A tool to listen on a KNX bus via TPUART and the Calimero Project suite and to dump the data from the packets into a Wireshark-Compatible file hex…

PoC exploit for CVE-2018-18778: arbitrary file read in mini_httpd 1.29 via empty Host header, affecting IoT devices from Huawei, Zyxel, and others.

Multi-threaded router fingerprinting tool that identifies web-exposed network devices by analyzing HTTP responses, headers, and favicon hashes for…

Offensive security tool for printer pentesting

CVE-2026-38426 — strcpy() Stack Buffer Overflow in Tasmota fetch_jpg() boundary[40] (Tasmota <= 15.3.0.3)

This firmware is an alternative to the EvilCrowRF default firmware. Module: CC1101 - Compatible Flipper Zero file.

Proof-of-concept for CVE-2026-90847, an authenticated RCE in iux_set.cgi via malicious .cfg tar upload that writes commands into crontab for…

Technical disclosure of CVE-2024-33676: weak authentication on Enel X JuiceBox EV chargers enabling PII extraction, settings manipulation, and OS…

This python file will decrypt the configurationFile used by hikvision cameras vulnerable to CVE-2017-7921.


Tool for RTSP that brute-forces routes and credentials, makes screenshots!

A ESP32-S3–based usb keylogger with wifi, easy DIY-able with widely available hardware.

Decrypts Hikvision IP camera configuration files extracted via CVE-2017-7921 authentication bypass, revealing user credentials and device settings.

In Paradox Security System IPR512 Web console login form page, attacker can input JavaScript string, such as "</script>" that will overwrite…

CVE-2018-9995_Batch_scanning_exp

DoS against Belkin smart plugs via crafted firmware injection

DoS against Belkin smart plugs via crafted firmware injection