
vxworks_hash
code to reverse vxworks 5.x password hashes

code to reverse vxworks 5.x password hashes

Proof-of-concept exploit and vulnerability disclosure for HiSilicon hi3520d DVR/NVR devices. Demonstrates RCE via web interface, backdoor…

This repository contains the results of my August 2020 research of Tiandy's IPC/NVR firmware. I found two vulnerabilities that could be used to…

Extracts hardware random keys from NEC Aterm router firmware images and QR codes to generate valid passwords for gaining shell access.

Proof-of-concept exploit for CVE-2024-44815 demonstrating extraction of plaintext router credentials from SPI flash via hardware teardown, UART…

Proof-of-concept exploit for CVE-2024-22894, demonstrating 3DES-encrypted root password extraction from Alpha Innotec/Novelan heatpump firmware,…

Documentation and reproduction steps for CVE-2022-24693: hardcoded credentials in Baicells Nova436Q and Neutrino 430 firmware, enabling remote SSH…

Tool to exploit CVE-2018-13341 and recover hidden account password on Crestron devices

Python3 exploit for CVE-2018-14847, an unauthenticated path traversal in MikroTik Winbox that extracts and decrypts admin credentials from user.dat.

Modern WiFi auditing library for ESP32 using advanced 802.11 techniques. Captures WPA/WPA2/WPA3 handshakes via PMKID extraction and CSA injection…

Python script to exploit CVE-2020-35391 on Tenda F3 V3/V4 routers, enabling unauthorized download of configuration, flash, and syslog files.