
CVE-2022-39073
Proof of concept for the command injection vulnerability affecting the ZTE MF286R router, including an RCE exploit.

Proof of concept for the command injection vulnerability affecting the ZTE MF286R router, including an RCE exploit.

Proof of Concept for the CVE-2026-22226

CVE proof of concept regarding the CVE-2025-45619 vulnerabillity.

In Paradox Security System IPR512 Web console login form page, attacker can input JavaScript string, such as "</script>" that will overwrite…


Python exploit for CVE-2021-36260 command injection in Hikvision web servers. Supports safe/unsafe vulnerability verification, remote command…

CVE-2023-40459 Unauthenticated DoS PoC Exploit

A vulnerability in fiberhome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-shared key) to be predicted…

Multi-threaded scanner to identify HikVision cameras vulnerable to CVE-2017-7921 by testing the ONVIF snapshot endpoint for unauthorized access.

D-LINK DIR-845L is vulnerable to information disclosure via the bsc_sms_inbox.php file.

The DGS-1510 Websmart switch series firmware has been found to have security vulneratiblies. The vulnerabilities include unauthenticated command…

An issue in Orbe ONetView Roteador Onet-1200 Orbe 1680210096 allows a remote attacker to escalate privileges via the servers response from status…

Original research and PoC for a pre-auth stack buffer overflow via unbounded sscanf scanset in the Netis NC63 ipFilterList handler

CVE-2024-42658 An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookies…

Proof-of-concept exploit for CVE-2024-1303, a path traversal vulnerability in Badger Meter's moni:tool that allows authenticated attackers to…

Hicip IP admin password reset script using CVE-2020-9529. This is made for educational purposes only of course.

TP-Link Archer AXE75 Authenticated Command Injection

CVE-2018-14714 PoC RCE