
Genzai
The IoT security toolkit to help identify IoT related dashboards and scan them for default passwords and vulnerabilities.

The IoT security toolkit to help identify IoT related dashboards and scan them for default passwords and vulnerabilities.

PoC exploit for CVE-2023-35803 unauthenticated buffer overflow in Aerohive HiveOS/Extreme Networks IQ Engine, enabling remote code execution on…

Proof-of-concept and technical analysis for CVE-2025-11142, an authenticated OS command injection in AXIS VAPIX mediaclip.cgi, with time-based and…

Intercepts and analyzes USB Mass Storage traffic at the block and file level, emulates USB devices, and supports custom Python stubs for security…

PoC exploit for CVE-2024-7029 in AVTech devices. Enables authentication bypass, remote code execution, vulnerability scanning, and interactive shell…

MITM proxy for TCP/TLS/DTLS/UDP traffic, with STARTTLS, IoT, Thick Client and more.

POC for TP-Link Archer C9 - Admin Password Reset and RCE (CVE-2017-11519)

PoC for the CVE-2024-41992 (RCE on devices running WiFi-TestSuite-DUT)

Advisory and technical analysis of CVE-2026-15469, a hard-coded RSA-512 mesh group private key in TP-Link Deco routers, including root cause, impact,…

Exploit for Remote Code Execution on GPON home routers (CVE-2018-10562) written in Python.

Proof-of-concept exploit for CVE-2022-30489, a stored XSS vulnerability in WAVLINK WN535G3 routers, demonstrating a POST-based attack via the…

Proof-of-concept exploit for CVE-2022-40881 targeting SolarView Compact devices. Uses fofa query for reconnaissance and payload delivery for…

Unauthenticated SSRF in Xiaomi Mi Router 4A Gigabit Edition (firmware 3.0.24) via Host Header Injection — CVE-2026-26898

Exploit for CVE-2017-7921 targeting Hikvision IP cameras, enabling remote credential extraction and device takeover via unauthenticated access.

The DGS-1510 Websmart switch series firmware has been found to have security vulneratiblies. The vulnerabilities include unauthenticated command…

Exploit script for CVE-2024-29972 Zyxel NAS backdoor account, combining with CVE-2024-29973 for unauthorized root access via NsaRescueAngel.

D-LINK ROUTER "MODEL NO: DIR-615" with "FIRMWARE VERSION:20.10" & "HARDWARE VERSION:T1

Scans for CVE-2026-24061 telnetd auth bypass, generating payloads and verifying root access on vulnerable GNU inetutils telnetd devices.