
trommel
TROMMEL: Sift Through Embedded Device Files to Identify Potential Vulnerable Indicators

A Curated list of Security Resources for all connected things

Advisory detailing active debug code in production Gardyn Home Kit cloud API, exposing development endpoints and embedded credentials, with…

Repository that tracks public exploits, vulnerabilities and advisories that I [co-]discovered or [co-]authored.

Self-hosted network discovery and search engine with continuous port scanning, deep protocol probing across ~100 services, local CVE matching, and…

A Zeek package for the passive detection of "Ripple20" vulnerabilities in the Treck TCP/IP stack.

A tool to manipulate Schneider Electric PLC archive files

Working exploit for Phoenix Contact CHARX SEC-3100 using Scapy raw Ethernet packets to trigger vulnerabilities and obtain an interactive connect-back…

CVE-2018-11311 | mySCADA myPRO 7 Hardcoded FTP Username and Password Vulnerability

Proof-of-concept exploit for authentication bypass via capture-replay in Dingtian DT-R002 relay, allowing unauthorized control of relays through HTTP…

PoC Modbus TCP exploit demonstrating spoofed writes to read-only coils in simulated PLCs, highlighting SCADA/ICS access control flaws.

An explanation and PoC to exploit CVE-2026-25938 Unauthenticated RCE Vulnerability on FUXA

CVE-2016-3962-Exploit

Modbus Packet Injection on Advantech WISE 4060LAN / IoT Gateway for door control

Schneider Electric Magelis HMI Resource Consumption Vulnerabilities [ICSA-16-308-02, CVE-2016-8367, CVE-2016-8374]

Critical vulnerability in Siemens RuggedCom ROS devices allowing attackers to derive a hidden factory account password from the device MAC address…

CVE-2018-7849

CVE-2018-7845