
CVE-2018-18852
Authenticated remote code execution exploit for CERIO routers (DT300N, DT100G, AMR-3204, WMR-200N) using vendor default credentials. Python PoC…

Authenticated remote code execution exploit for CERIO routers (DT300N, DT100G, AMR-3204, WMR-200N) using vendor default credentials. Python PoC…

A key generator for Zyxel VMG8825-T50

Supporting material for the "Hunting Bugs In The Tropics" DEFCON 30 talk

This repository holds interesting bits and pieces related to research I performed on wireless presentation devices manufactured by Awindinc and…

CVE-2018-11311 | mySCADA myPRO 7 Hardcoded FTP Username and Password Vulnerability

Exploit for CVE-2017-14262 targeting Samsung NVR devices: extracts admin MD5 password hash via unauthenticated CGI request and logs in with the hash…

By the Way is an exploit that enables a root shell on Mikrotik devices running RouterOS versions:

Xiongmai XM530 IP Camera Hardcoded RTSP Credentials Exposure

An issue in Shenzen Tenda Technology CP3V2.0 V11.10.00.2311090948 allows a local attacker to obtain sensitive information via the password component.

Weaponized exploit script for CVE-2020-35575, a password-disclosure vulnerability in TP-Link router web interfaces, granting remote administrative…

CVE-2024-57040 is a security vulnerability found in certain TP-Link TL-WR845N router models. Specifically, it involves a "hardcoded" password for the…

Simulates a Matter commissioning code brute-force attack (CVE-2026-23005) using Python to demonstrate missing rate limiting and lockout on 8-digit…

Macally WIFISD2

CERIO RCE CVE-2018-18852, authenticated (vendor defaults) web-based RCE as root user.

Proof-of-concept exploit for CVE-2020-25749 targeting Rubetek cameras with hardcoded Telnet credentials, enabling remote root shell access and full…

Proof-of-concept of vulnerability found in Totolink A720R router

It is the details of CVE-2025-45466

Exploit code for CVE-2023-28810