
CVE-2026-25938-FUXA-Unauthenticated-RCE
An explanation and PoC to exploit CVE-2026-25938 Unauthenticated RCE Vulnerability on FUXA

An explanation and PoC to exploit CVE-2026-25938 Unauthenticated RCE Vulnerability on FUXA


ICS-Park Smart Park Management System v2.0


Proof-of-concept reproducing CVE-2021-22681's hardcoded-key flaw and validating a per-device mutual TLS/CRL fix over simulated EtherNet/IP, with IEC…

Real world and CTFs exploiting web/binary POCs.

Repository that tracks public exploits, vulnerabilities and advisories that I [co-]discovered or [co-]authored.

Python scripts for security assessment of industrial PLCs: scanning, enumeration, control, and exploitation of Beckhoff, Siemens, Schneider,…

To reproduce CVE-2021-31630

PoC C&C for the Industroyer malware

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

ScadaFlare Authenticated RCE Exploit Framework for ScadaBR (CVE-2021-26828) OpenPLC ScadaBR

CVE-2018-11517 | mySCADA myPRO v7.0.46 has another vulnerability to discover all projects in the system.

Authenticated users can upload arbitrary files (e.g. .html, .svg) as profile images in OpenPLC Runtime. These files are publicly accessible without…

Description and exploit of CVE-2023-33831 affecting FUXA web-based Process Visualization (SCADA/HMI/Dashboard) software.

POC exploit for CVE-2026-25895 FUXA Unauthenticated Path Traversal -> Arbitrary File Write -> RCE

There is a path injection vulnerability in OpenPLC-v3, which arises from the program not performing any validity checks on the file path parameters…

Modbus Packet Injection on Advantech WISE 4060LAN / IoT Gateway for door control