
CVE-2018-9995_dvr_credentials
Exploit tool for CVE-2018-9995 that extracts DVR credentials via HTTP request with cookie bypass, targeting multiple vendor devices for security…

Exploit tool for CVE-2018-9995 that extracts DVR credentials via HTTP request with cookie bypass, targeting multiple vendor devices for security…

Go-based brute-force exploit tool targeting Hikvision cameras vulnerable to CVE-2021-36260, with multi-threaded scanning and configurable…

Exploit tool for CVE-2018-9995 that extracts credentials from vulnerable DVR devices via Google dorking and direct IP access.

Exploit tool for CVE-2018-13341 that recovers the hidden 'crengsuperuser' password from Crestron TSW-XX60 devices using the MAC address, enabling…

Disclosure of CVE-2025-45466 detailing hardcoded plaintext SSH credentials in Unitree Go1 robotic dog firmware, enabling remote code execution,…

Proof-of-concept of vulnerability found in Totolink A720R router

Proof-of-concept exploit for CVE-2025-65427: missing rate limiting on Dbit N300 T1 Pro router login API enabling brute-force attacks and…

Proof-of-concept exploit for CVE-2020-25749 targeting Rubetek cameras with hardcoded Telnet credentials, enabling remote root shell access and full…

The IoT security toolkit to help identify IoT related dashboards and scan them for default passwords and vulnerabilities.

Proof-of-concept exploit for CVE-2023-43261 targeting Milesight industrial routers. Demonstrates credential leakage via unprotected system logs and…

Authenticated remote code execution exploit for CERIO routers (DT300N, DT100G, AMR-3204, WMR-200N) using vendor default credentials. Python PoC…

Python-based key generator for obtaining Zyxel VMG8825-T50 supervisor passwords using reverse-engineered authentication functions.

Supporting material for the "Hunting Bugs In The Tropics" DEFCON 30 talk

This repository holds interesting bits and pieces related to research I performed on wireless presentation devices manufactured by Awindinc and…

CVE-2018-11311 disclosure and exploit for hardcoded FTP credentials (myscada:Vikuk63) in mySCADA myPRO 7 HMI/SCADA software, enabling unauthorized…

Hikvision IP camera access bypass exploit, developed by golang.

Exploit for CVE-2017-14262 targeting Samsung NVR devices: extracts admin MD5 password hash via unauthenticated CGI request and logs in with the hash…

Simulates a Matter commissioning code brute-force attack (CVE-2026-23005) using Python to demonstrate missing rate limiting and lockout on 8-digit…