


This repository contains a few vulnerabilities that were found and reported during vulnerability assessments.

Authenticated users can upload arbitrary files (e.g. .html, .svg) as profile images in OpenPLC Runtime. These files are publicly accessible without…

APOLOGEE is a Python script and Metasploit module that enumerates a hidden directory on Siemens APOGEE PXC BACnet Automation Controllers (all…

Open-source forensics framework for analyzing Industrial PLC metadata and project files. Scans for suspicious artifacts in ICS environments to…

Description and exploit of CVE-2023-33831 affecting FUXA web-based Process Visualization (SCADA/HMI/Dashboard) software.

Paracosme is a zero-click remote memory corruption exploit that compromises ICONICS Genesis64 which was demonstrated successfully on stage during the…

Modbus Slave缓冲区溢出漏洞CVE-2022-1068分析与复现

Analyzing and Reproducing the Command Injection Vulnerability (CVE-2023-0861) in NetModule Routers

Repository that tracks public exploits, vulnerabilities and advisories that I [co-]discovered or [co-]authored.

A pre-authenticated RCE exploit for Inductive Automation Ignition

Low Interaction Mobile Honeypot

ISAF aims to be a framework that provides the necessary tools for the correct security audit of industrial (OT) environments.