
Xiaomi-C200-Firmware-Analysis
From UART to Root: Breaking Into the Xiaomi C200 via U-Boot

From UART to Root: Breaking Into the Xiaomi C200 via U-Boot

Python exploit for CVE-2021-46381 targeting D-Link DAP-1620 arbitrary file read vulnerability with FOFA-based device discovery.

Nortek Control Linear eMerge E3-Series 信息泄露


PoC Script for CVE-2024-25832: Exploit chain reverse shell, information disclosure (root password leak) + unrestricted file upload in DataCube3

PoC exploit for CVE-2018-18778: arbitrary file read in mini_httpd 1.29 via empty Host header, affecting IoT devices from Huawei, Zyxel, and others.

CVE-2026-38426 — strcpy() Stack Buffer Overflow in Tasmota fetch_jpg() boundary[40] (Tasmota <= 15.3.0.3)

CVE-2026-38427 — Integer Wraparound → Heap Buffer Overflow in Tasmota fetch_jpg() uint16_t (Tasmota <= 15.3.0.3)

CVE-2026-38422 — Remote Code Execution via Combined Buffer Overflows in Tasmota fetch_jpg() (Tasmota <= 15.3.0.3)