
SirepRAT
Remote Command Execution as SYSTEM on Windows IoT Core (releases available for Python2.7 & Python3)

Remote Command Execution as SYSTEM on Windows IoT Core (releases available for Python2.7 & Python3)

Chrome extension that uses vulnerabilities CVE-2021-33044 and CVE-2021-33045 to log in to Dahua cameras without authentication.

This tool is used for encrypt backdoor,shellcode,socks5 proxy generation,Information retrieval and POC arrangement for various architecture devices

Python-Based Pentesting CLI Tool

Exploit for command injection vulnerability found in uhttpd binary from TP-Link Tapo c200 IP camera

A ESP32-S3–based usb keylogger with wifi, easy DIY-able with widely available hardware.

Asymmetric cryptography library for generating signed URLs on embedded devices, enabling time-limited resource access using PSA Crypto API with…

POC - CVE-2024–10914- Command Injection Vulnerability in `name` parameter for D-Link NAS

TP-Link Archer AXE75 Authenticated Command Injection

Proof-of-concept exploit for CVE-2022-31898, a command injection vulnerability in GL-iNet routers (firmware < 3.215). Provides reverse shell via…

CVE-2018-19537

Lightweight telnet honeypot for capturing IoT malware samples and identifying active command-and-control infrastructure, designed for educational…

Proof of concept for the command injection vulnerability affecting the ZTE MF286R router, including an RCE exploit.

Proof-of-concept exploit for CVE-2024-7120 command injection vulnerability in RAISECOM gateway devices. Provides exploitation details, affected…

🔐 "PWNTAPO: Unveiling Command Injection in TP-Link Tapo C200 Cameras (<= v1.1.16 Build 211209)" 🔓

PoC Script for CVE-2022-36267: Exploits an unauthenticated remote command injection vulnerability in Airspan AirSpot 5410 antenna.

Authenticated command injection exploit for Tenda HG9 routers. Provides interactive remote shell access via Python script for penetration testing and…

Dahua IPC/VTH/VTO devices auth bypass exploit