

Decoder/encoder for Ubiquiti AirMAX wireless protocol frames; parse pcap/live captures, discover devices, scan for vulnerable firmware, craft…

Damn Vulnerable Drone is an intentionally vulnerable drone hacking simulator based on the popular ArduPilot/MAVLink architecture, providing a…

Proof-of-concept tool demonstrating zero-authentication Bluetooth RFCOMM access bypass in vulnerable thermal printers

Scans Bluetooth Low Energy devices for Fast Pair vulnerabilities (CVE-2025-36911), testing if accessories accept unencrypted Key-Based Pairing…

This script can be used to check if a Bluetooth device is vulnerable to CVE-2025-36911.

Brute-force attack tool against WPS registrar PINs to recover WPA/WPA2 passphrases, supporting online brute force and offline Pixie Dust attacks on…

Remote code execution exploit for CVE-2024-57366 targeting WAVLINK routers via MAC address validation bypass and command injection, with automatic…

Bluetooth keyboard injection exploit for CVE-2023-45866 targeting Android, iOS, macOS, and Linux devices. Simulates HID device to execute automated…

Bluetooth Classic HID injection exploit for CVE-2023-45866, enabling unauthenticated keystroke injection against vulnerable BlueZ-based Linux systems.

cve based on vulnerable cisco's Archer A7 routers

Proof-of-concept exploit for CVE-2021-1965, a WiFi zero-click RCE in Android's MBSSID parsing, causing buffer overflow and device reboot.

Proxmark3 Lua script for attacking vulnerable Protectimus SLIM NFC TOTP hardware tokens

An experimental script PoC for Kr00k vulnerability (CVE-2019-15126)

HT-WPS Breaker (High Touch WPS Breaker)

use the Apple CoreText exploit (CVE-2012-3716) and launch an AP to affect all devices within wifi range