
awesome-connected-things-sec
A Curated list of Security Resources for all connected things

A Curated list of Security Resources for all connected things

Real world and CTFs exploiting web/binary POCs.

Small script to retrieve passwords from many types of Moxa device, including NPort, OnCell, MGate, etc.

proof of Concept (PoC) exploit for CVE-2021-31630, targeting the OpenPLC service running on the WifineticTwo box on the Hack The Box platform.

Analyzing and Reproducing the Command Injection Vulnerability (CVE-2023-0861) in NetModule Routers

Modbus Slave缓冲区溢出漏洞CVE-2022-1068分析与复现

Technical vulnerability analysis and CVE briefing for CVE-2026-9645 affecting ScadaBR.

Purdue Model for Industrial Control System (ICS) Environments (Turkish)

Active Scanning and Information Gathering in ICS/SCADA Networks using Network Mapper (NMAP) (Turkish)

This repository includes the code and files needed to test and execute a PoC for CVE-2025-41656

Benign proof-of-concept for CVE-2026-36226, a cross-site scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 Admin Dashboard Create…

SpiderControl SCADA Web Server File Upload Vulnerability

POC Exploit for CVE-2021-31630 written in Python3 and using C reverse shell with non-blocking mode

Authenticated users can upload arbitrary files (e.g. .html, .svg) as profile images in OpenPLC Runtime. These files are publicly accessible without…

Security Vulnerability - Kardex Mlog MCC