
ufuzz
Automated UPnP fuzzing tool for discovering vulnerabilities in embedded systems, with HTTP fuzzing support and custom crash monitoring.

Automated UPnP fuzzing tool for discovering vulnerabilities in embedded systems, with HTTP fuzzing support and custom crash monitoring.

Proof-of-concept of vulnerability found in Totolink A720R router

WebKit+Kernel exploit chain for all PS Vita firmwares

The IoT security toolkit to help identify IoT related dashboards and scan them for default passwords and vulnerabilities.

Pre-Authenticated Full Root Remote Command Execution in Voltronic Power SNMP Web Pro 1.1

An explanation and PoC to exploit CVE-2026-25938 Unauthenticated RCE Vulnerability on FUXA

Proof-of-concept exploit for pre-authentication path traversal in Zephyr RTOS HTTP server static-fs handler, demonstrating directory traversal via…

CVE-2026-54477 disclosure detailing missing security headers (CSP, X-Frame-Options) in Gardyn IoT admin panel enabling clickjacking and XSS, with…

Documentation of CVE-2026-36438: a vulnerability in Intelbras VIP 1230 B/D G4 devices allowing remote attackers to obtain administrator account…

Exploiting TP-Link Archer CR-700 Router. (Responsibly Disclosed to TP-Link)

Hack The CCTV | DVRs; Credentials Exposed | CVE-2018-9995

Proof-of-concept exploit for CVE-2022-30489, a stored XSS vulnerability in WAVLINK WN535G3 routers, demonstrating a POST-based attack via the…

Proof-of-concept exploit for CVE-2021-35296 targeting PTCL Modem HG150-Ub, demonstrating a specific vulnerability for security testing and research.

Public disclose of several stored XSS vulnerabilities in the Sensaphone WEB600 (CVE-2024-55040)

In Paradox Security System IPR512 Web console login form page, attacker can input JavaScript string, such as "</script>" that will overwrite…

Zeek package for detecting the vulnerable Boa web server via HTTP Server header inspection. Raises a notice upon observation of vulnerable versions.

Proof-of-concept for stored cross-site scripting (XSS) vulnerability in D-Link DSL-2730E routers via the username parameter on the maintenance…

TP-LINK Multiple HTML Injection Vulnerabilities