
CVE-2026-25938-FUXA-Unauthenticated-RCE
An explanation and PoC to exploit CVE-2026-25938 Unauthenticated RCE Vulnerability on FUXA

An explanation and PoC to exploit CVE-2026-25938 Unauthenticated RCE Vulnerability on FUXA

Working exploit for Phoenix Contact CHARX SEC-3100 using Scapy raw Ethernet packets to trigger vulnerabilities and obtain an interactive connect-back…

Repository that tracks public exploits, vulnerabilities and advisories that I [co-]discovered or [co-]authored.

Zeek package for passive detection of Ripple20 vulnerabilities in Treck TCP/IP stack, alerting on device artifacts and exploit attempts.

CVE-2018-11311 disclosure and exploit for hardcoded FTP credentials (myscada:Vikuk63) in mySCADA myPRO 7 HMI/SCADA software, enabling unauthorized…

Modbus Packet Injection on Advantech WISE 4060LAN / IoT Gateway for door control

Python exploit for CVE-2018-7854 targeting Schneider Electric Modicon M580/M340 PLCs. Executes remote exploitation against industrial control systems…

Python exploit for CVE-2018-7849 targeting Schneider Electric Modicon PLCs (M580, M340, Premium, Quantum) for remote exploitation of industrial…

Python exploit for CVE-2018-7852 targeting Schneider Electric Modicon PLCs (M580, M340, Premium, Quantum) with remote code execution via crafted…

Python exploit for CVE-2018-7848 targeting Schneider Electric Modicon PLCs (M580, M340, Premium, Quantum) with command-line usage for remote…

Python exploit for CVE-2018-7846 targeting Schneider Electric Modicon PLCs (M580, M340, Premium, Quantum) for security testing of industrial control…

Python exploit for CVE-2018-7845 targeting Schneider Electric Modicon PLCs (M580, M340, Premium, Quantum) for security testing and vulnerability…

Python exploit for CVE-2018-7844 targeting Schneider Electric Modicon PLCs (M580, M340, Premium, Quantum) with remote code execution via crafted…

Python exploit for CVE-2018-7842 targeting Schneider Electric Modicon PLCs, enabling remote start/stop operations on industrial control systems.

Proof-of-concept exploit for CVE-2016-3962 targeting Meinberg NTP Time Server web interface, with CVE-2016-3989 privilege escalation to root.

Self-hosted network discovery and search engine with continuous port scanning, deep protocol probing across ~100 services, local CVE matching, and…

Proof-of-concept exploit for CVE-2023-31716, a Local File Inclusion vulnerability in FUXA SCADA/HMI software versions <= 1.1.12, enabling arbitrary…

Proof-of-concept exploit for a remote buffer overflow vulnerability in KNX ETS4 management software, demonstrating ROP-based code execution via…