
misfortune-cookie
Interactive PoC suite for CVE-2014-9222 (Misfortune Cookie) and related router exploits, featuring detection, auth bypass, DoS, and RCE modules with…

Interactive PoC suite for CVE-2014-9222 (Misfortune Cookie) and related router exploits, featuring detection, auth bypass, DoS, and RCE modules with…

AsyncIO Scanner & Exploitation Framework for CVE-2026-24061 (Telnet NEW_ENVIRON Auth Bypass). Features high-concurrency discovery, passive…

Scans for CVE-2026-24061 telnetd auth bypass, generating payloads and verifying root access on vulnerable GNU inetutils telnetd devices.

TP-Link Archer BE800 V1 — Parental Control LAN RCE

From a bare PCB to root: hardware-hacking a ZyXEL P-870HN (BCM6368) over UART — CVE-2025-0890 + CVE-2024-40891, on my own hardware.

PoC for CVE-2026-8023: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

0day PoC for CVE-2025-1739

Technical breakdown of CVE-2026-34472, an auth bypass via leaked credentials affecting ZTE H188A routers.

Vulnerability research write-up on CVE-2017-7921 — a critical unauthenticated auth bypass in Hikvision IP cameras/DVRs/NVRs, covering root cause,…

HikVision Auth Bypass CVE, tool is able to extract credentials, and take snapshots based on magic cookie or supplied credentials.

Python exploit for Dahua device authentication bypass (CVE-2021-33044). Sends crafted malicious data packets to bypass login and gain unauthorized…

Dahua IPC/VTH/VTO devices auth bypass exploit

Exploit for Dahua IPC/VTH/VTO devices that bypasses identity authentication by sending crafted malicious packets, allowing unauthorized access.