
CVE-2026-25938-FUXA-Unauthenticated-RCE
An explanation and PoC to exploit CVE-2026-25938 Unauthenticated RCE Vulnerability on FUXA

An explanation and PoC to exploit CVE-2026-25938 Unauthenticated RCE Vulnerability on FUXA

Towards Large-Scale Emulation of IoT Firmware for Dynamic Analysis

This project demonstrates the publicly disclosed CVE-2018-9995 vulnerability found in multiple embedded DVR devices.

Real world and CTFs exploiting web/binary POCs.

Offensive security research hub aggregating original vulnerability advisories, CVE proof-of-concept exploits, conference talks, and internal tooling…

Read out-of-bounds PoC for miniupnpd <= v2.1

A flexible internet crawler used for scanning technologies, instances and vulnerabilities worldwide across the internet.


Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…


CVE-2025-22912

Reolink Duo 2 WiFi v1.0.280 - Account Enumeration Vulnerability

POC - CVE-2024–10914- Command Injection Vulnerability in `name` parameter for D-Link NAS

A technical case study and exploitation analysis of the Authentication Bypass vulnerability in TP-Link TL-WR840N firmware (CVE-2018-12633).

Flexwatch-CVE

CVE-2023-49965 | SpaceX / Starlink Router Gen 2 XSS