
uberscan
Security program for recovering passwords and pen-testing servers, routers and IoT devices using brute-force password attacks.

Security program for recovering passwords and pen-testing servers, routers and IoT devices using brute-force password attacks.

A PoC exploit for CVE-2017-8225 - GoAhead System.ini Leak

CamOver is a camera exploitation tool that allows to disclosure network camera admin password.

RomBuster is a router exploitation tool that allows to disclosure network router admin password.

A tool which exploits a backdoor in Hikvision camera firmwares circa 2014-2016 to help the owner change a forgotten password.

CVE-2023-43261 - Credential Leakage Through Unprotected System Logs and Weak Password Encryption

Exploit for CVE-2017-14262 targeting Samsung NVR devices: extracts admin MD5 password hash via unauthenticated CGI request and logs in with the hash…

A vulnerability in fiberhome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-shared key) to be predicted…

POC for TP-Link Archer C9 - Admin Password Reset and RCE (CVE-2017-11519)

PoC Script for CVE-2024-25832: Exploit chain reverse shell, information disclosure (root password leak) + unrestricted file upload in DataCube3

CVE-2024-57040 is a security vulnerability found in certain TP-Link TL-WR845N router models. Specifically, it involves a "hardcoded" password for the…

Proof-of-concept exploit for CVE-2024-22894, demonstrating 3DES-encrypted root password extraction from Alpha Innotec/Novelan heatpump firmware,…

Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while…

Some Assmann manufactured IP-Cams leak the administrator password in their backup.

Argus Surveillance DVR v4.0 employs weak password encryption.

DVR username password recovery.

Documentation of CVE-2026-36438: a vulnerability in Intelbras VIP 1230 B/D G4 devices allowing remote attackers to obtain administrator account…

Proof-of-concept exploit for an authentication bypass in HP 1920 Series switches, allowing unauthenticated admin password change via crafted HTTP…