A repository containing vulnerabilities I have reported that have been assigned a CVE (or are pending one).
Each folder includes a write-up and an exploit (PoC || GTFO!).
Some folders also contain a copy of the vulnerable software for research and reproduction purposes.
Enjoy ;)
| CVE ID | Description | Exploit |
|---|---|---|
| CVE-2026-????? | Yealink meetingboard unauthenticated arbitrary file write | RCE |
| CVE-2026-20452 | MediaTek WPS kernel driver heap overflow | RCE |
| CVE-2025-13943 | Zyxel authenticated command injection in log export CGI | RCE |
| CVE-2025-13942 | Zyxel unauthenticated command injection in UPnP daemon | RCE |
| CVE-2025-40634 | TP-Link archer ax50 wan stack overflow | RCE |
| CVE-2024-2188 | TP-Link archer ax50 stored XSS via UPnP | JS exec |
| CVE-2021-4045 | TP-Link tapo c200 unauthentiacted RCE | RCE |