
unleashed-firmware
Custom firmware for Flipper Zero enabling Sub-GHz radio, NFC/RFID emulation, infrared, and BadUSB attack features for hardware security testing.

Custom firmware for Flipper Zero enabling Sub-GHz radio, NFC/RFID emulation, infrared, and BadUSB attack features for hardware security testing.

Custom firmware framework for PS Vita that patches the kernel, disables code-signing checks, and provides a hooking API for developing kernel and…

Modular framework for IoT malware implantation research, providing tools for firmware modification, serial port debugging, software analysis, and spy…

Abstracts and expedites the process of backdooring stock firmware images for consumer/SOHO routers

ARM32 Linux kernel privilege escalation exploit for CVE-2026-43499 (GhostLock futex UAF) targeting Huawei Watch 4 Pro with multiple exploitation…

Exploit vulnerable Brother printers via CVE-2017-7588, collect data, and develop custom firmware implants for attack simulation.

Authenticated remote code execution exploit for TP-Link Archer C5 routers via malicious configuration file upload. Injects OS commands with root…

A fully implemented kernel exploit for the PS4 on 5.05FW

Fully chained kernel exploit for the PS Vita on firmwares 3.65-3.68

Exploit for Sagemcom F@ST 3890 cable modem implementing Cable Haunt vulnerability to achieve remote code execution via WebSocket-based buffer…

Python-based exploit development framework with payloads, encoders, and connect-back servers, focused on MIPS CPU architecture but designed for…

Let's hijack our bootchain - CVE-2021-30327

Framework for Digiduck Development Boards running ATTiny85 processors and micronucleus bootloader!

Local privilege escalation exploit chain for LG WebOS TVs (CVE-2022-23731) targeting 32-bit SoCs via V8 engine exploitation and shellcode injection.

Displays an old-school crack-intro animation on compromised Canon and Lexmark printers, with SDL2 and WebAssembly builds for portability and study.

A fully implemented kernel exploit for the PS4 on 5.05FW

Collection of "modchip" designs for launching payloads via the Tegra RCM bug (CVE-2018-6242)

D-Link DSL-3782 Code Execution (Proof of Concept)