
Injection-vulnerability-in-Paradox-Security-Systems-IPR512-CVE-2023-24709-PoC
In Paradox Security System IPR512 Web console login form page, attacker can input JavaScript string, such as "</script>" that will overwrite…

In Paradox Security System IPR512 Web console login form page, attacker can input JavaScript string, such as "</script>" that will overwrite…

This firmware is an alternative to the EvilCrowRF default firmware. Module: CC1101 - Compatible Flipper Zero file.


Multi-threaded router fingerprinting tool that identifies web-exposed network devices by analyzing HTTP responses, headers, and favicon hashes for…

Nortek Control Linear eMerge E3-Series 信息泄露

D-LINK DIR-845L is vulnerable to information disclosure via the bsc_sms_inbox.php file.

Decrypts Hikvision IP camera configuration files extracted via CVE-2017-7921 authentication bypass, recovering user credentials from weakly encrypted…

Decrypts Hikvision IP camera configuration files extracted via CVE-2017-7921 authentication bypass, revealing user credentials and device settings.

CVE-2026-38427 — Integer Wraparound → Heap Buffer Overflow in Tasmota fetch_jpg() uint16_t (Tasmota <= 15.3.0.3)

CVE-2026-38426 — strcpy() Stack Buffer Overflow in Tasmota fetch_jpg() boundary[40] (Tasmota <= 15.3.0.3)

CVE-2026-38422 — Remote Code Execution via Combined Buffer Overflows in Tasmota fetch_jpg() (Tasmota <= 15.3.0.3)

Asus Router Arbitrary File Write to Remote Code Execution PoC - Fk Mirai

Python exploit for CVE-2021-46381 targeting D-Link DAP-1620 arbitrary file read vulnerability with FOFA-based device discovery.

DoS against Belkin smart plugs via crafted firmware injection

DoS against Belkin smart plugs via crafted firmware injection

CVE-2018-9995_Batch_scanning_exp

HikVision Auth Bypass CVE, tool is able to extract credentials, and take snapshots based on magic cookie or supplied credentials.

Proof-of-concept exploits for CVE-2025-52688: unauthenticated command injection and arbitrary file read vulnerabilities in Alcatel AP13161 enterprise…