
ghostlock-cve-2026-43499
CVE-2026-43499 (GhostLock) — Linux kernel futex PI rt_mutex UAF ARM32 privilege escalation research targeting Huawei Watch 4 Pro (kernel 5.4.210)

CVE-2026-43499 (GhostLock) — Linux kernel futex PI rt_mutex UAF ARM32 privilege escalation research targeting Huawei Watch 4 Pro (kernel 5.4.210)

An experimental webkit-based kernel exploit (Arb. R/W) for the PS5 on <= 4.51FW

Remote exploit for MikroTik RouterOS v6 that abuses IPC vulnerabilities and a ROP chain to escalate privileges, execute code, and spawn a reverse…

WebKit+Kernel exploit chain for all PS Vita firmwares

A PS5 hypervisor exploit for 1.xx-2xx firmwares.

Public disclosure of Tecnovision DlxSpot Player 4 vulnerabilities: hardcoded SSH credentials, SQL injection, and arbitrary file upload to remote code…

A fully implemented kernel exploit for the PS4 on 5.05FW

Fully chained kernel exploit for the PS Vita on firmwares 3.65-3.68

A fully implemented kernel exploit for the PS4 on 5.05FW

This repository contains the results of my August 2020 research of Tiandy's IPC/NVR firmware. I found two vulnerabilities that could be used to…

Exploit for privilege escalation on MitraStar GPT-2541GNAC-N1 routers using command injection in deviceinfo show file command to spawn a root shell…

Proof-of-concept exploit for CVE-2026-36355: unauthenticated kernel memory read/write via debug IOCTLs in Realtek rtl819x Jungle SDK Wi-Fi driver,…

Disclosure of CVE-2025-45466 detailing hardcoded plaintext SSH credentials in Unitree Go1 robotic dog firmware, enabling remote code execution,…

Local privilege escalation exploit chain for LG WebOS TVs (CVE-2022-23731) targeting 32-bit SoCs via V8 engine exploitation and shellcode injection.

An issue in Orbe ONetView Roteador Onet-1200 Orbe 1680210096 allows a remote attacker to escalate privileges via the servers response from status…

CVE-2025-29628, CVE-2025-29629, CVE-2025-29630, CVE-2025-29631

Proof-of-concept exploit for CVE-2024-36821 demonstrating local privilege escalation on a router via writable cron scripts and UART access, enabling…

ARM32 Linux kernel privilege escalation exploit for CVE-2026-43499 (GhostLock futex UAF) targeting Huawei Watch 4 Pro with multiple exploitation…