
CVE-2019-19781
Exploit module for CVE-2019-19781 targeting Citrix ADC, integrated with Router Scan for automated vulnerability scanning and exploitation.

Exploit module for CVE-2019-19781 targeting Citrix ADC, integrated with Router Scan for automated vulnerability scanning and exploitation.

Automated firmware analysis and exploit toolkit for CVE-2022-27255, a Realtek eCos SDK SIP ALG buffer overflow affecting 30+ router models. Includes…

CVE-2017-17215 HuaWei Router RCE (NOT TESTED)

Netis router RCE exploit ( CVE-2019-19356)

Persistent XSS on Comtrend AR-5387un router

TP-Link Router Authenticated RCE Exploit (CVE-2022-30075) Bu araç, TP-Link Archer AX50 ve bazı diğer TP-Link router modellerinde bulunan…

Proof-of-concept for stored XSS vulnerability in Asus DSL-N14U router firmware, with exploit payloads and list of 70+ vulnerable ASP pages for…

Arris Router Firmware 9.1.103 - Remote Code Execution (RCE) (Authenticated) POC Exploit (CVE-2022-45701)

Remote buffer overflow exploit for D-Link DIR-619L router (CVE-2024-9570) targeting the formEasySetTimezone function for penetration testing and…

CVE-2026-12960 - Improper Export of Android Application Components in the ASUS Router app (com.asus.aihome). PoC, exploit APK, video, and vendor…

Exploit code for CVE-2021-27246 targeting TPLink Archer routers, demonstrated at Pwn2Own 2020 Tokyo. Includes proof-of-concept for remote code…

An exploit for Four-Faith routers to get a reverse shell

Pre-authentication Remote Code Execution exploit for TP-Link Omada ER605 router via DDNS client daemon (cmxddnsd)

Proof-of-concept exploit for CVE-2026-36960, a CSRF vulnerability in U-SPEED Router firmware allowing unauthorized configuration changes via forged…

Writeup for Tenda AC15 router firmware rehosting and remote command execution (CVE-2020-10987) exploit replication.

Standalone exploit for CVE-2025-55182 achieving unauthenticated RCE in Next.js App Router via React Server Components Flight deserialization, with…

Proof-of-concept exploit for CVE-2025-55182, demonstrating unauthenticated RCE in Next.js App Router via server-side object injection in React Server…

Proof-of-concept exploit for CVE-2025-43865 demonstrating pre-render data spoofing in React Router framework mode, enabling data injection during…