
CVE-2026-19745
Learn how I found my first two CVEs by pure accident.

Learn how I found my first two CVEs by pure accident.

Documentation of CVE-2026-30081, a high-severity cleartext transmission vulnerability in Quantum Networks QN-I-470 router firmware 6.1.1.B1, allowing…

Proof-of-concept exploit for CVE-2026-36960, a CSRF vulnerability in U-SPEED Router firmware allowing unauthorized configuration changes via forged…

Proof-of-concept exploit for CVE-2026-36959, a missing rate limiting vulnerability in U-SPEED Router firmware allowing brute-force attacks on the…

Proof-of-concept for CVE-2026-36958, a denial-of-service vulnerability in U-SPEED Router firmware that exhausts resources via concurrent HTTP…

Proof-of-concept for CVE-2026-36957, a denial-of-service vulnerability in Dbit Router firmware via HTTP flood on the Boa web server, causing resource…

Proof-of-concept for CVE-2026-36956, a CSRF vulnerability in Dbit Router firmware allowing unauthorized configuration changes via forged requests.

Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

Exploiting TP-Link Archer CR-700 Router. (Responsibly Disclosed to TP-Link)

Proof-of-concept for a denial-of-service attack via cache poisoning by forcing SPA mode, targeting CVE-2025-43864 in React Router applications.

Proof-of-concept exploit for CVE-2025-43865 demonstrating pre-render data spoofing in React Router framework mode, enabling data injection during…

D-Link DIR-845L router is vulnerable to Cross Site Scripting (XSS) via /htdocs/webinc/js/bsc_sms_inbox.php.

CTF challenge replicating CVE-2025-31137 in Remix/React Router Express. Learn to exploit a server-side vulnerability to find the admin flag.

This is a fast, asynchronous Python tool that fingerprints domains for likely Next.js App Router / React Server Components (RSC) infrastructure. (I…

CSRF vulnerability in FD602GW-DX-R410 router allows remote attackers to reboot the device via a crafted POST request to /boaform/admin/formReboot…

Proof-of-concept for authenticated stored cross-site scripting (XSS) vulnerability in Multilaser RE 170 router firmware 2.2.6733, with reproduction…

A Firefox extension for detecting React2Shell vulnerabilities (CVE-2025-55182 & CVE-2025-66478) in web applications.

Persistent XSS on Comtrend AR-5387un router