
misfortune-cookie
Interactive PoC suite for CVE-2014-9222 (Misfortune Cookie) and related router exploits, featuring detection, auth bypass, DoS, and RCE modules with…

Interactive PoC suite for CVE-2014-9222 (Misfortune Cookie) and related router exploits, featuring detection, auth bypass, DoS, and RCE modules with…

CVE-2024-40617 Exploit PoC

Static firmware reverse engineering of CVE-2015-1187: unauthenticated command injection in D-Link DIR-820L. MIPS root filesystem extraction with…

Tenda Technology Co., Ltd NVR_4H: CH3 v2.1.V27.5.58.6 was discovered to contain a hardcoded cryptographic key.

Proof of concept IoT/Ham Radio mesh network with global routing over the internet

CVE-2019-2215 & DirtyCOW exploit automation + post-root debloat + Magisk modules for Sony BRAVIA KDL-43W800C

Exploit for TP-Link AX10/AX1500 stack buffer overflow in CWMP (TR-069) enabling remote code execution via ret2libc with ASLR bypass. Includes…

Auerswald COMpact 8.0B Backdoors exploit

Exploit for CVE-2020-8597 targeting RM2100 routers, providing proof-of-concept code for remote code execution via buffer overflow in the router's web…

Ghidra loader for the MediaTek md1img modem firmware image format

By the Way is an exploit that enables a root shell on Mikrotik devices running RouterOS versions:

Syma X5SW Telemetry and Transmissor

Unauthenticated access in the default configuration of the D-Link DWR-M972V

CVE-2017-14948 for D-Link 880 Firmware

Xiongmai XM530 IP Camera Hardcoded RTSP Credentials Exposure

Reverse Engineering of the Shining App Mask

🛡️ AI-powered portable cybersecurity & pentesting assistant built on ESP32-S3 (LilyGO T-Embed CC1101 & T-Watch S3). Features voice-controlled RF…

Original research and PoC for a pre-auth Base64-decoded password stack buffer overflow in Netis NC63 login.cgi