
CVE-2026-76070
Original research and non-destructive PoC for a pre-auth Base64-decoded password stack buffer overflow in Netis NC63 login.cgi

Original research and non-destructive PoC for a pre-auth Base64-decoded password stack buffer overflow in Netis NC63 login.cgi

Proof-of-concept and writeup showing how to retrieve Wi-Fi SSID/password from a D-Link Komfy smart switch over BLE by reversing the iOS app’s custom…

A tool which exploits a backdoor in Hikvision camera firmwares circa 2014-2016 to help the owner change a forgotten password.

CVE-2023-43261 - Credential Leakage Through Unprotected System Logs and Weak Password Encryption

D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root…

POC for TP-Link Archer C9 - Admin Password Reset and RCE (CVE-2017-11519)

Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while…

Proof-of-concept exploit for CVE-2024-4232 targeting plaintext password storage in Digisol DG-GR1321 routers. Demonstrates extraction of credentials…

Proof-of-concept exploit for CVE-2024-22894, demonstrating 3DES-encrypted root password extraction from Alpha Innotec/Novelan heatpump firmware,…

Some Assmann manufactured IP-Cams leak the administrator password in their backup.

CVE-2026-34474: unauthenticated ETHCheat=1 requests leak the admin password and Wi-Fi PSK from ZTE H298A/H108N routers.

A PoC exploit for CVE-2017-8225 - GoAhead System.ini Leak

CVE-2017-7921 exploit. Allows admin password retrieval and automatic snapshot download.

Exploit for CVE-2017-14262 targeting Samsung NVR devices: extracts admin MD5 password hash via unauthenticated CGI request and logs in with the hash…

A full functional WiFi NAT Router (and now also a WiFi Repeater)

A vulnerability in fiberhome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-shared key) to be predicted…

Proof-of-concept for stored cross-site scripting (XSS) vulnerability in D-Link DSL-2730E routers via the username parameter on the maintenance…

Weaponized exploit script for CVE-2020-35575, a password-disclosure vulnerability in TP-Link router web interfaces, granting remote administrative…