
HimitsuShell
shell script protector (obfuscation, embedded interpreter, DRM) - invisible to kernel tracing

shell script protector (obfuscation, embedded interpreter, DRM) - invisible to kernel tracing

rt26cx21x64.sys exploit (Realtek PCIe GbE/2.5GbE/5GbE family)

Security advisory for TOTOLINK a720r buffer overflow vulnerability

Original research and PoC for a pre-auth stack buffer overflow via unbounded sscanf scanset in the Netis NC63 ipFilterList handler

my advisory, poc, slides and scripts related to IoT/protocol security

A Curated list of Security Resources for all connected things

Fuzzing IoT Devices Using the Router TL-WR902AC as Example

IoT Security research conducted during my internship at IIIT Allahabad, leading to CVE-2026-65893, CVE-2026-65894, and the CERT-In Vulnerability Note…

An unofficial Humax IR4000HD terminal client with enhanced features.

CVE-2025-70962 PoC

Independent IoT security research, vulnerability disclosures, and PoCs focusing on firmware analysis, hardware interfaces, and cryptographic flaws.

Reverse engineering research and custom firmware for Allwinner V3-based IoT cameras, including firmware parsers, an AVIOCTRL client, and a…

Proof of Concept for CVE-2025-15545

Local streaming tool for cheap WiFi cameras that bypasses cloud services and phone apps. Discovers cameras on your network, authenticates via PPPP…

Proof-of-concept exploit for CVE-2020-12124 targeting Wavlink AC1200 router, demonstrating unauthenticated command injection and stack buffer…

Flipper Zero app for infrared electronic shelf-label (ESL) protocol research, featuring custom image transmission, NFC tag scanning, and a web-based…

Run Radmin VPN on Linux via Wine — custom driver, TAP bridge, zero packet loss

BLE-based Fitbit research tool for authentication replay, encrypted activity dump decryption, memory/firmware extraction, and custom firmware…