
CVE-2021-4045
🔐 "PWNTAPO: Unveiling Command Injection in TP-Link Tapo C200 Cameras (<= v1.1.16 Build 211209)" 🔓

🔐 "PWNTAPO: Unveiling Command Injection in TP-Link Tapo C200 Cameras (<= v1.1.16 Build 211209)" 🔓

CVE-2025-57174 Unauthenticated Remote Command Execution

A minimal authenticated reverse shell framework for reaching hosts with outbound internet access.

Rejetto HFS (HTTP File Server) is a simple web file server that facilitates file sharing over a network or the internet.

According to researchers with Rapid7, over 110,000 devices appear on internet, which run stable Samba versions, while 92,500 seem to run unstable…

A self hosted virtual browser that runs in docker and uses WebRTC.


Remote Command Execution as SYSTEM on Windows IoT Core (releases available for Python2.7 & Python3)

Proof of concept for the command injection vulnerability affecting the ZTE MF286R router, including an RCE exploit.

A PoC tool for exploiting CVE-2024-7029 in AvTech devices, enabling RCE, vulnerability scanning, and an interactive shell.

Netis router RCE exploit ( CVE-2019-19356)

D-Link NAS Command Execution Exploit

CVE-2026-13768: Privileged iothubowner IoT Hub credential — fleet enumeration, device RCE, home-network pivot — Gardyn (ICSA-26-183-03)

Exploit loader for Remote Code Execution w/ Payload on GPON Home Gateway devices (CVE-2018-10562) written in Python.

TP-Link Tapo c200 ver <1.1.15 - Remote Code Execution (RCE)

This script exploits a remote command execution vulnerability in the TPLink WR840N router, using the configure function IPv6 protocol.