
CVE-2026-64824-PoC
CVE-2026-64824 — Home Assistant backup-restore symlink path traversal → root RCE. First working PoC, verified on real HA 2026.5.4 (sitecustomize.py…

CVE-2026-64824 — Home Assistant backup-restore symlink path traversal → root RCE. First working PoC, verified on real HA 2026.5.4 (sitecustomize.py…

Exploits Hikvision CVE-2017-7921 to demonstrate unauthenticated credential disclosure and admin interface exposure, promoting patches and secure…

Lightweight Python utility to enable telnet on Netgear routers (R7000, R7500) using LAN MAC and admin credentials. Useful for penetration testing,…

POC for TP-Link Archer C9 - Admin Password Reset and RCE (CVE-2017-11519)

CVE-2026-54477 disclosure detailing missing security headers (CSP, X-Frame-Options) in Gardyn IoT admin panel enabling clickjacking and XSS, with…

CVE-2026-28767 disclosure: missing authentication on Gardyn Home Kit cloud API admin notifications endpoint, exposing internal system data and…

Proof-of-concept exploit for CVE-2025-45619, an information disclosure vulnerability in AVer PTC310UV2 camera firmware that exposes plaintext admin…

Proof-of-concept exploit for CVE-2025-41646, a critical authentication bypass in RevPi WebStatus ≤ v2.4.5, exploiting weak type comparison to gain…

Proof-of-concept exploit for CVE-2025-1738 demonstrating cleartext admin password exposure in Trivision NC227WF cameras via unauthenticated local…

Proof-of-concept exploit for CVE-2024-40617 targeting Fujitsu M2M GW1500 IoT gateway. Provides remote exploitation via admin password authentication…

Self-hosted WireGuard mesh VPN with browser-based admin portal, Winbox proxy, WebSSH, and WebProxy for managing remote devices and IoT infrastructure…

CVE-2026-34474: unauthenticated ETHCheat=1 requests leak the admin password and Wi-Fi PSK from ZTE H298A/H108N routers.

Proof-of-concept exploit for CVE-2022-31269 targeting Nortek Linear eMerge E3-Series, enabling information disclosure to access the admin dashboard.

Exploit script for CVE-2017-7921 targeting vulnerable IP cameras. Retrieves admin credentials via config decryption and enables automated snapshot…

Exploit for CVE-2017-14262 targeting Samsung NVR devices: extracts admin MD5 password hash via unauthenticated CGI request and logs in with the hash…

Proof-of-concept exploit for CVE-2017-14263 in Honeywell NVR devices. Demonstrates session hijacking and privilege escalation from guest to admin via…

Technical disclosure of a predictable session cookie vulnerability (CVE-2025-48461) in Advantech WISE-4060 IoT portal, enabling bruteforce…

TP-LINK Multiple HTML Injection Vulnerabilities