
unleashed-firmware
Custom firmware for Flipper Zero enabling Sub-GHz radio, NFC/RFID emulation, infrared, and BadUSB attack features for hardware security testing.

Custom firmware for Flipper Zero enabling Sub-GHz radio, NFC/RFID emulation, infrared, and BadUSB attack features for hardware security testing.

CVE-2026-64824 — Home Assistant backup-restore symlink path traversal → root RCE. First working PoC, verified on real HA 2026.5.4 (sitecustomize.py…

CVE-2026-43499 (GhostLock) — Linux kernel futex PI rt_mutex UAF ARM32 privilege escalation research targeting Huawei Watch 4 Pro (kernel 5.4.210)

An explanation and PoC to exploit CVE-2026-25938 Unauthenticated RCE Vulnerability on FUXA

Pre-Authenticated Full Root Remote Command Execution in Voltronic Power SNMP Web Pro 1.1

CVE-2026-53921 odhcpd stack overflow exploit with dual-vector (IA_NA/IA_PD) payloads, MIPS/ARM shellcode, ROP chains, SOCKS5 proxy, persistence, and…

ARM32 Linux kernel privilege escalation exploit for CVE-2026-43499 (GhostLock futex UAF) targeting Huawei Watch 4 Pro with multiple exploitation…

Let's hijack our bootchain - CVE-2021-30327

Remote buffer overflow exploit framework for Epson printers (CVE-2026-39047). Features payload generation with obfuscation, fuzzing, transport…

Proof-of-concept exploit for CVE-2026-8836, a critical stack-based buffer overflow in lwIP's SNMPv3 USM handler. Constructs oversized authentication…

Proof-of-concept exploit for CVE-2026-36356: unauthenticated OS command injection in MeiG Smart FORGE_SLT711 GoAhead web server, enabling root-level…

Exploit implementation for CVE-2018-6242 targeting the Nintendo Switch Tegra X1 boot ROM via USB Recovery Mode, enabling arbitrary payload execution…

Remote code execution exploit for CVE-2024-57366 targeting WAVLINK routers via MAC address validation bypass and command injection, with automatic…

Proof-of-Concept for CVE-2025-2082, demonstrating function pointer overwrite via signed-to-unsigned integer conversion bug in Tesla VCSEC, leading to…

VM-based code obfuscation toolkit: transpiles LLVM bitcode to RISC-V64 payloads and executes them in a custom rv64i interpreter to hinder static and…

Proof-of-concept exploit for CVE-2025-2620, a critical stack-based buffer overflow in D-Link DAP-1620 routers enabling unauthenticated remote code…

Proof-of-concept exploit for CVE-2024-35106, a stack buffer overflow in NEXTU FLETA AX1500 Wi-Fi 6 router. Demonstrates denial-of-service and…

Exploits for Tenda Ac8v4 stack-based overflow to Remote-Code Execution via Mipsel Ropping (CVE-2023-33669 - CVE-2023-33675)