
wifi-pineapple-cloner-builds
Pre-built firmware images for cloning the Wi-Fi Pineapple TETRA onto OpenWrt-compatible hardware, enabling wireless auditing and red team operations…

Pre-built firmware images for cloning the Wi-Fi Pineapple TETRA onto OpenWrt-compatible hardware, enabling wireless auditing and red team operations…

Build your own custom WiFi Pineapple Tetra firmware tailored to any based MIPS 24Kc architecture router. (WiFi Pineapple Tetra DIY)

Custom firmware for Flipper Zero enabling Sub-GHz radio, NFC/RFID emulation, infrared, and BadUSB attack features for hardware security testing.

Convert GL-AR150 routers into WiFi Pineapple NANO devices for wireless penetration testing, featuring PineAP support, custom OpenWrt firmware, and…

This firmware is an alternative to the EvilCrowRF default firmware. Module: CC1101 - Compatible Flipper Zero file.

Modular framework for black-box CAN bus analysis enabling ECU discovery, MitM testing, fuzzing, and brute-force attacks on automotive networks.

Framework for black-box CAN bus network analysis, enabling security assessment, fuzzing, and vulnerability discovery in automotive embedded systems.

Modular framework for IoT malware implantation research, providing tools for firmware modification, serial port debugging, software analysis, and spy…

Abstracts and expedites the process of backdooring stock firmware images for consumer/SOHO routers

Open-source hardware USB trigger for fault injection and side-channel analysis. Sniffs USB packets, generates glitch waveforms with adjustable…

Modular DIY CAN Bus adapter with slcan protocol support for SocketCAN and python-can. Offensive firmware variant enables spoofing, bus-off, and…

Black-box security evaluation of five ISP cable modem/router gateways, analyzing firmware images and documenting 35+ vulnerabilities including…

This repository contains the results of my August 2020 research of Tiandy's IPC/NVR firmware. I found two vulnerabilities that could be used to…

Proof-of-concept exploit for CVE-2023-20126 targeting Cisco SPA phone adapters. Uploads malicious firmware to gain a root shell on port 23000/tcp via…

Proof-of-concept exploit for CVE-2023-22906, demonstrating default root Telnet access on Hero Qubo Smart Doorbell firmware HCD01_02_V1.38_20220125,…

Command injection exploit for TP-Link Tapo C200 camera (CVE-2021-4045) providing root shell access via UART and reverse-engineered uhttpd binary…

Technical disclosure of four unauthenticated RCE vulnerabilities (CVE-2020-25782/3/4/5) in Accfly wireless security cameras, including stack/heap…

CVE-2021-21735 write-up: ZTE ZXHN H168N V3.5 wizard-page information leak, firmware routing flaw, and the path from exposed PPPoE/WLAN data to full…