
reverse-skill
AI-powered skill router pack for reverse engineering, penetration testing, and security research. Routes AI agents to correct methodologies and…

AI-powered skill router pack for reverse engineering, penetration testing, and security research. Routes AI agents to correct methodologies and…

POC for CVE-2025-29384

Unauthenticated SSRF in Xiaomi Mi Router 4A Gigabit Edition (firmware 3.0.24) via Host Header Injection — CVE-2026-26898

cve-2024-21413

Proof-of-concept exploit for CVE-2025-55182, demonstrating unauthenticated RCE in Next.js App Router via server-side object injection in React Server…

CVE-2025-55182 React Server Components Remote Code Execution Exploit Tool

Unified Security Research Tool

Improper Access Control on D-Link DIR-605L router

TP-Link ER7206 Omada Gigabit VPN Router uhttpd freeStrategy Command injection Vulnerability

Build repo from Universal Wifi pineapple hardware cloner

CVE-2022-1388 - F5 Router RCE Replica

Proof-of-concept scripts for CVE-2023-1389, an unauthenticated command injection in TP-Link Archer AX21, providing file transfer and reverse shell…

Arris Router Firmware 9.1.103 - Remote Code Execution (RCE) (Authenticated) POC Exploit (CVE-2022-45701)

This script exploits a vulnerability (XSS) in the TPLink WR840N router, using a field for injecting javascript code.

This script exploits a remote command execution vulnerability under the oal_setIp6DefaultRoute component in the TPLink WR840N router.

Exploit code for CVE-2021-27246 targeting TPLink Archer routers, demonstrated at Pwn2Own 2020 Tokyo. Includes proof-of-concept for remote code…

Proof-of-concept exploit for CVE-2018-20162: sandbox escape in Digi TransPort LR54 LTE router via SIGINT handling flaw, yielding root shell access.

Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…