
CVE-2024-22894
Proof-of-concept exploit for CVE-2024-22894, demonstrating 3DES-encrypted root password extraction from Alpha Innotec/Novelan heatpump firmware,…

Proof-of-concept exploit for CVE-2024-22894, demonstrating 3DES-encrypted root password extraction from Alpha Innotec/Novelan heatpump firmware,…

Some Assmann manufactured IP-Cams leak the administrator password in their backup.

CVE-2026-34474: unauthenticated ETHCheat=1 requests leak the admin password and Wi-Fi PSK from ZTE H298A/H108N routers.

CVE-2017-7921 exploit. Allows admin password retrieval and automatic snapshot download.

A full functional WiFi NAT Router (and now also a WiFi Repeater)

DVR username password recovery.

Documentation of CVE-2026-36438: a vulnerability in Intelbras VIP 1230 B/D G4 devices allowing remote attackers to obtain administrator account…

Detailed CVE-2026-8697 writeup with POC exploit for a login rate-limit bypass on TP-Link Archer C64 routers via a debug SSH service, enabling…

PoC Script for CVE-2024-25832: Exploit chain reverse shell, information disclosure (root password leak) + unrestricted file upload in DataCube3

CamOver is a camera exploitation tool that allows to disclosure network camera admin password.

RomBuster is a router exploitation tool that allows to disclosure network router admin password.

Security program for recovering passwords and pen-testing servers, routers and IoT devices using brute-force password attacks.