
Loracrack
LoRaWAN session cracker - A PoC for exploiting weak or shared Application Keys

LoRaWAN session cracker - A PoC for exploiting weak or shared Application Keys

Proof-of-concept and technical analysis for CVE-2025-11142, an authenticated OS command injection in AXIS VAPIX mediaclip.cgi, with time-based and…

Sets up a local Tapo C200 using CVE-2021-4045

POC VIDEO - https://youtu.be/hNzmkJj-ImM?si=NF0yoSL578rNy7wN

CVE-2017-7921 exploit. Allows admin password retrieval and automatic snapshot download.

Python exploit for TP-Link TL-WR840N RCE (CVE-2022-25064) via crafted IPv6 address payload in the router's CGI interface, enabling remote command…

TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a crafted HTTP Header…

CVE-2026-43499 for the Meta Quest

Proof-of-concept exploit for authentication bypass via capture-replay in Dingtian DT-R002 relay, allowing unauthorized control of relays through HTTP…

Advisory and technical analysis of CVE-2026-15469, a hard-coded RSA-512 mesh group private key in TP-Link Deco routers, including root cause, impact,…

Proof-of-concept exploit for TP-Link TDDP authentication bypass (CVE-2026-0834) that sends crafted packets to execute administrative commands like…

Some Assmann manufactured IP-Cams leak the administrator password in their backup.

Proof-of-concept code (Bash and Python) for CVE-2025-65856 where ONVIF implementation in in Xiongmai XM530 IP cameras allows for unauthenticated …

Details regarding the Z-Wave S0-No-More attack

Exploit for CVE-2023-37621 targeting unauthorized access in Fronius Datalogger Web 2.0.5-4, allowing attackers to retrieve sensitive device…

Proof-of-concept exploit for a buffer overflow vulnerability (CVE-2024-44596) in Netis N5VN AC1200 routers, causing a denial of service by crashing…

This script exploits a vulnerability (IoF) in the TPLink WR840N router, using a field for injecting code in the module DNS.

Telnet default credentials can lead to information disclosure and denial-of-service (DoS) attacks.