
CVE-2018-9995_dvr_credentials
(CVE-2018-9995) Get DVR Credentials

(CVE-2018-9995) Get DVR Credentials

IEEE 802.15.4/ZigBee Security Research Toolkit


The OWASP SecureTea Project provides a one-stop security solution for various devices (personal computers / servers / IoT devices)

A smart gateway to stop cyber criminals - Sponsored by Falcon Guard

Remote Command Execution as SYSTEM on Windows IoT Core (releases available for Python2.7 & Python3)


Tool for especially scanning nearby devices and execute a given command on its own system while the target device comes in range.

Manipulate Chromecast Devices in your Network

Python telnet honeypot for catching botnet binaries

This project intends to provide a series of tools to craft, parse, send, analyze and crack a set of LoRaWAN packets in order to audit or pentest the…

A login bypass(CVE-2019-18371) and a command injection vulnerability(CVE-2019-18370) in Xiaomi Router R3G up to version 2.28.23.


A tool for malicious behavior detection in IoT devices

Bash script exploiting CVE-2018-9995 to extract credentials from vulnerable DVRs via web interface, supporting multiple DVR brands for automated…

Proof-of-concept exploit and analysis for command injection and hardcoded backdoor credentials in D-Link NAS devices, enabling unauthenticated remote…

my advisory, poc, slides and scripts related to IoT/protocol security

CVE-2019-6487. A command injection vulnerability in TP-Link WDR5620 Series up to verion 3.