

Used to quickly test the Hikvision CVE-2017-7921 vulnerability with FOFA, and provide the login account and password, and output a JSON file.

Cameradar 攻击进入 RTSP 视频监控摄像机

异步网络侦察引擎,用于大规模服务发现和指纹识别。识别未受保护的服务(RTSP摄像头、VNC、FTP)并提供实时终端仪表盘,带有认证状态检测。

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…

CVE-2026-43499 (GhostLock) — Linux 内核 futex PI rt_mutex UAF ARM32 权限提升研究,针对华为 Watch 4 Pro(内核 5.4.210)

针对海康威视 IP 摄像头的 CVE-2017-7921 Python 漏洞利用脚本,可通过精心构造的 HTTP 请求执行未授权用户枚举、快照捕获和配置文件下载。

针对 CVE-2026-73673(Netis NC63 路由器中的一个未认证固件更新漏洞)的非破坏性 PoC 与技术文档,包含复现步骤和证据工件。

关于在 FUXA 上利用 CVE-2026-25938 未认证 RCE 漏洞的说明与 PoC

Complete firmware vulnerability analysis for CVE-2020-9373 Netgear R6400 UPnP stack overflow, including unpacking, reverse engineering, static…

从裸 PCB 到 root:通过 UART 硬件破解 ZyXEL P-870HN (BCM6368) — CVE-2025-0890 + CVE-2024-40891,在我自己的硬件上。

Voltronic Power SNMP Web Pro 1.1 中的未认证完整 Root 远程命令执行

面向 ESP32 的开源无线研究平台。



开源物联网平台 - 设备管理、数据采集、处理和可视化。