
unleashed-firmware
Custom firmware for Flipper Zero enabling Sub-GHz radio, NFC/RFID emulation, infrared, and BadUSB attack features for hardware security testing.

Custom firmware for Flipper Zero enabling Sub-GHz radio, NFC/RFID emulation, infrared, and BadUSB attack features for hardware security testing.

Security research on a consumer IP camera built on the Fullhan FH8626V100 SoC (model AJL30PG0803).

Framework for Digiduck Development Boards running ATTiny85 processors and micronucleus bootloader!

DropEngine provides a malleable framework for creating shellcode runners, allowing operators to choose from a selection of components and combine…

Predatory ESP32 Firmware

A Streamlined FTP-Driven Command and Control Conduit for Interconnecting Remote Systems.

React2Shell Exploitation Tool (CVE-2025-55182)

Python-based exploit development framework with payloads, encoders, and connect-back servers, focused on MIPS CPU architecture but designed for…

Elite exploitation toolkit for CVE-2025-55182 (React Server Components RCE). Async polymorphic payloads, advanced WAF/CDN bypass, proxy rotation,…

React2Shell Vulnerability

D-Link DSL-3782 Code Execution (Proof of Concept)

Toolkit for implant attack of IoT devices

React2Shell CVE-2025-55182: unauthenticated unsafe deserialization in React Server Components leading to reliable remote code execution via the…

CVE-2026-43499 (GhostLock) — Linux kernel futex PI rt_mutex UAF ARM32 privilege escalation research targeting Huawei Watch 4 Pro (kernel 5.4.210)

Exploit for CVE-2026-40003, an arbitrary memory write vulnerability in ZXIC/Sanechips ZX297520V3 SoC BootROM, enabling code execution via USB…

Rust implementation of the Fusée Gelée exploit (CVE-2018-6242) for Tegra processors.

Advanced React Server Components RCE scanner for CVE-2025-55182. Features: multi-stage fingerprinting, vulnerability verification, DNS exfiltration,…

Pre-Authenticated Full Root Remote Command Execution in Voltronic Power SNMP Web Pro 1.1