
tiandy-research
This repository contains the results of my August 2020 research of Tiandy's IPC/NVR firmware. I found two vulnerabilities that could be used to…

This repository contains the results of my August 2020 research of Tiandy's IPC/NVR firmware. I found two vulnerabilities that could be used to…

ARM32 Linux kernel privilege escalation exploit for CVE-2026-43499 (GhostLock futex UAF) targeting Huawei Watch 4 Pro with multiple exploitation…

Hardware hacking guide demonstrating UART access, U-Boot exploitation, and firmware extraction on the Xiaomi C200 IoT camera, achieving root shell…

Disclosure of CVE-2025-45466 detailing hardcoded plaintext SSH credentials in Unitree Go1 robotic dog firmware, enabling remote code execution,…

A PS5 hypervisor exploit for 1.xx-2xx firmwares.

Exploit for privilege escalation on MitraStar GPT-2541GNAC-N1 routers using command injection in deviceinfo show file command to spawn a root shell…

A fully implemented kernel exploit for the PS4 on 5.05FW

Fully chained kernel exploit for the PS Vita on firmwares 3.65-3.68

An experimental webkit-based kernel exploit (Arb. R/W) for the PS5 on <= 4.51FW

Exploit for CVE-2022-38694 that bypasses signature verification to unlock bootloader on Unisoc/Spreadtrum devices, executing code with BootROM…

WebKit+Kernel exploit chain for all PS Vita firmwares

Remote exploit for MikroTik RouterOS v6 that abuses IPC vulnerabilities and a ROP chain to escalate privileges, execute code, and spawn a reverse…

Proof-of-concept exploit for CVE-2015-6639, demonstrating privilege escalation in Qualcomm's QSEE TrustZone via PRDiag commands on Android devices.

Local privilege escalation exploit chain for LG WebOS TVs (CVE-2022-23731) targeting 32-bit SoCs via V8 engine exploitation and shellcode injection.

A fully implemented kernel exploit for the PS4 on 5.05FW

An implementation of baton drop (CVE-2022-21894) for armv7 (MSM8960)

Automated exploit for Macally WIFISD2 travel router (CVE-2020-29669) enabling guest-to-root privilege escalation via password reset manipulation and…

Proof-of-concept exploit for CVE-2024-36821 demonstrating local privilege escalation on a router via writable cron scripts and UART access, enabling…