
CVE-2021-27246_Pwn2Own2020
Exploit code for CVE-2021-27246 targeting TPLink Archer routers, demonstrated at Pwn2Own 2020 Tokyo. Includes proof-of-concept for remote code…

Exploit code for CVE-2021-27246 targeting TPLink Archer routers, demonstrated at Pwn2Own 2020 Tokyo. Includes proof-of-concept for remote code…

Tool to exploit CVE-2018-13341 and recover hidden account password on Crestron devices

Proof-of-concept exploit for CVE-2023-20126 targeting Cisco SPA phone adapters. Uploads malicious firmware to gain a root shell on port 23000/tcp via…

This repository contains the results of my August 2020 research of Tiandy's IPC/NVR firmware. I found two vulnerabilities that could be used to…

Card calculator and Proxmark3 Plugin for writing and/or simulating every card type that Doppelgänger Community, Pro, Stealth, and MFAS support.

A coordinated disclosure and security advisory on Fermax Intercom DTML Injection vulneraiblity. Special thanks to Fermax International for prompt…

PoC exploit chain for pre-authentication remote code execution on SonicWall SMA 100 appliances exploiting CVE-2023-44221 and CVE-2024-38475.

Proof-of-concept exploit for CVE-2025-2620, a critical stack-based buffer overflow in D-Link DAP-1620 routers enabling unauthenticated remote code…

Epson Printer RAW Protocol Exploit Framework

CVE-2026-53921 – odhcpd Stack Overflow (CVSS 9.8) 🛡️ Vuln detailed and comprehensive Write-Up and Verifier & Multi-exploit for OpenWrt DHCPv6 RCE.…

Proof-of-concept demonstrating hardcoded root credentials (admin/system) in Tenda HG21 XPON modem firmware, enabling unauthorized root access via…

A session-unique RISC-V ISA — every boot speaks a different dialect. Old binaries become invalid. Malware cannot persist.

🛡️ AI-powered portable cybersecurity & pentesting assistant built on ESP32-S3 (LilyGO T-Embed CC1101 & T-Watch S3). Features voice-controlled RF…

Security research on a consumer IP camera built on the Fullhan FH8626V100 SoC (model AJL30PG0803).

Proof of Concept of CVE-2025-48507. The security flaw can be leveraged by Non-Secure software (e.g., Linux) to break Trust Zone and gain access to…

Proof-of-concept exploit for CVE-2025-69515 demonstrating static GPS spoofing on JXL 9-inch Android infotainment units via SDR-based signal…

CVE-2026-35904 / CVE-2026-35905 / CVE-2026-35906 — Unauth RCE, Hardcoded Root Creds & Telnet Enable in T3 Technology CPE

SETROOTCERTIFICATE (write /etc/cert.pem.1) + APPLYAPP (RC_SERVICE execution). Refs: CVE-2025-2492, CVE-2024-12912, CVE-2025-59366; runZero;…