
CVE-2021-26828_ScadaBR_RCE
Proof-of-concept exploit for CVE-2021-26828 enabling authenticated remote code execution on ScadaBR SCADA systems via JSP file upload. Supports…

Proof-of-concept exploit for CVE-2021-26828 enabling authenticated remote code execution on ScadaBR SCADA systems via JSP file upload. Supports…

Static analysis tool that sifts through embedded device firmware to identify vulnerable indicators including SSH/SSL keys, IPs, URLs, shell scripts,…

A tool to manipulate Schneider Electric PLC archive files

PoC exploit for CVE-2025-69985: authentication bypass leading to RCE in FUXA SCADA ≤1.2.8. Includes a modular Python exploit with interactive shell,…

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

Ultimate Internet of Things/Industrial Control Systems reconnaissance tool.

Multi-domain penetration testing tool for IoT, ICS, and IT networks. Provides modules for network scanning, traffic manipulation, proxy setup, and…

Industrial control system security testing tool that enumerates and rewrites SCADA controller registers (coils, inputs, holding registers) in safe,…

Footprinting and fingerprinting tool for robotic systems, including ROS, ROS2, SROS, and industrial routers. Scans networks, detects nodes, topics,…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Multi-protocol honeypot simulator supporting 50+ network services with deep interaction, TCP/UDP/ICMP logging, JA3 fingerprinting, and virtual…

Systematic fuzzer for Sparkplug B MQTT protocol implementations. Tests all 19 metric data types, injects malicious payloads, spoofs device…

Instrumented fuzzer for PLC-based ICS control applications, targeting Codesys runtime on Wago controllers to uncover memory corruption and…

A pre-authenticated RCE exploit for Inductive Automation Ignition

Python exploit for CVE-2025-69985 targeting FUXA SCADA software. Sends crafted JSON payload to /api/runscript endpoint to bypass authentication and…

Exploit for CVE-2021-31630 in OpenPLC, providing a Python script and manual steps to achieve remote code execution via malicious ST file upload and…

Proof-of-concept exploit for CVE-2025-41646, a critical authentication bypass in RevPi WebStatus ≤ v2.4.5, exploiting weak type comparison to gain…

OpenPLC 3 WebServer Authenticated Remote Code Execution.