
neko
A self hosted virtual browser that runs in docker and uses WebRTC.

A self hosted virtual browser that runs in docker and uses WebRTC.

CVE-2026-13768: Privileged iothubowner IoT Hub credential — fleet enumeration, device RCE, home-network pivot — Gardyn (ICSA-26-183-03)

A minimal authenticated reverse shell framework for reaching hosts with outbound internet access.

CVE-2025-57174 Unauthenticated Remote Command Execution

PoC exploit for CVE-2024-7029 in AVTech devices. Enables authentication bypass, remote code execution, vulnerability scanning, and interactive shell…

Rejetto HFS (HTTP File Server) is a simple web file server that facilitates file sharing over a network or the internet.

D-Link NAS Command Execution Exploit

🔐 "PWNTAPO: Unveiling Command Injection in TP-Link Tapo C200 Cameras (<= v1.1.16 Build 211209)" 🔓

Proof of concept for the command injection vulnerability affecting the ZTE MF286R router, including an RCE exploit.

TP-Link Tapo c200 ver <1.1.15 - Remote Code Execution (RCE)

This script exploits a remote command execution vulnerability in the TPLink WR840N router, using the configure function IPv6 protocol.

According to researchers with Rapid7, over 110,000 devices appear on internet, which run stable Samba versions, while 92,500 seem to run unstable…

Remote Command Execution as SYSTEM on Windows IoT Core (releases available for Python2.7 & Python3)

Netis router RCE exploit ( CVE-2019-19356)


Exploit loader for Remote Code Execution w/ Payload on GPON Home Gateway devices (CVE-2018-10562) written in Python.