
fufu-sec
Framework for Uninvited Frequency Usage

Framework for Uninvited Frequency Usage

POC for the CVE-2026-1459 which payload changes root SSH password.

MikroTik Password Recovery Tool

Automated Cisco SNMP Enumeration, Brute Force, Configuration Download and Password Cracking

Supermicro IPMI/BMC Cleartext Password Scanner

Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.

Exploit for CVE-2024-21754 targeting insufficient password hashing in FortiOS and FortiProxy, enabling privileged attackers to decrypt backup files…

Fully functional script for brute forcing SSH and trying credentials - CVE-2018-15473

PoC of CVE-2018-14847 Mikrotik Vulnerability using simple script

Proof-of-concept exploit for CVE-2024-22894, demonstrating 3DES-encrypted root password extraction from Alpha Innotec/Novelan heatpump firmware,…

CVE-2026-34474: unauthenticated ETHCheat=1 requests leak the admin password and Wi-Fi PSK from ZTE H298A/H108N routers.

Critical vulnerability in Siemens RuggedCom ROS devices allowing attackers to derive a hidden factory account password from the device MAC address…

This module sniff username and password of unprotected protocols.

A full functional WiFi NAT Router (and now also a WiFi Repeater)

Proof-of-concept exploit for CVE-2016-6515, crashing OpenSSH servers via oversized password payloads that exhaust CPU resources during hash…

Proof-of-concept exploit for CVE-2018-14847 (MikroTik WinBox vulnerability) enabling arbitrary file read and plaintext password extraction via TCP/IP…

Python script for SSH username enumeration using timing-based analysis to identify valid accounts on a target server.

Detailed CVE-2026-8697 writeup with POC exploit for a login rate-limit bypass on TP-Link Archer C64 routers via a debug SSH service, enabling…