hardware
hardware 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
Coship Wireless Router 4.0.0.x/5.0.0.x – WiFi Password Reset
# Exploit Title: Coship Wireless Router – Wireless SSID Unauthenticated Password Reset
Zyxel VMG3312-B10B DSL-491HNU-B1B v2 Modem – Cross-Site Request Forgery
# Exploit Title: Zyxel VMG3312-B10B DSL-491HNU-B1B v2 modem CSRF Exploit
devolo dLAN 550 duo+ Starter Kit – Remote Code Execution
devolo dLAN 550 duo+ Starter Kit Remote Code Execution
devolo dLAN 550 duo+ Starter Kit – Cross-Site Request Forgery
devolo dLAN 550 duo+ Starter Kit Cross-Site Request Forgery
BEWARD N100 H.264 VGA IP Camera M2.1.6 – Arbitrary File Disclosure
BEWARD N100 H.264 VGA IP Camera M2.1.6 Arbitrary File Disclosure
BEWARD N100 H.264 VGA IP Camera M2.1.6 – Remote Code Execution
BEWARD N100 H.264 VGA IP Camera M2.1.6 Root Remote Code Execution
BEWARD N100 H.264 VGA IP Camera M2.1.6 – Cross-Site Request Forgery (Add Admin)
BEWARD N100 H.264 VGA IP Camera M2.1.6 CSRF Add Admin Exploit
BEWARD N100 H.264 VGA IP Camera M2.1.6 – RTSP Stream Disclosure
BEWARD N100 H.264 VGA IP Camera M2.1.6 Unauthenticated RTSP Stream Disclosure
Cisco Firepower Management Center 6.2.2.2 / 6.2.3 – Cross-Site Scripting
# Exploit Title: Cisco Firepower Management Center Cross-Site Scripting (XSS) Vulnerability
Cisco RV300 / RV320 – Information Disclosure
# Exploit Title: 6coRV Exploit
Sricam gSOAP 2.8 – Denial of Service
#!/bin/bash
AirTies Air5341 Modem 1.0.0.12 – Cross-Site Request Forgery
# Exploit Title: AirTies Air5341 1.0.0.12 Modem CSRF Exploit & PoC
Cisco RV320 Dual Gigabit WAN VPN Router 1.4.2.15 – Command Injection
RedTeam Pentesting discovered a command injection vulnerability in the
Zyxel NBG-418N v2 Modem 1.00(AAXM.6)C0 – Cross-Site Request Forgery
NBG-418N v2 Modem CSRF Exploit & PoC
GL-AR300M-Lite 2.27 – (Authenticated) Command Injection / Arbitrary File Download / Directory Traversal
# Exploit Title: GL-AR300M-Lite Authenticated Command injection - Arbitrary file download - Directory Traversal
Fortinet FortiGate FortiOS < 6.0.3 - LDAP Credential Disclosure
#/usr/bin/python3
Lenovo R2105 – Cross-Site Request Forgery (Command Execution)
# Exploit Title: Lenovo R2105 Remote Code Execution through CSRF
Hootoo HT-05 – Remote Code Execution (Metasploit)
require 'msf/core'
Across DR-810 ROM-0 – Backup File Disclosure
#Exploit Title: Across DR-810 ROM-0 Backup - File Disclosure(Sensitive Information)
ZTE MF65 BD_HDV6MF65V1.0.0B05 – Cross-Site Scripting
# Exploit Title: Reflected Cross-Site Scripting on ZTE MF65
Heatmiser Wifi Thermostat 1.7 – Cross-Site Request Forgery (Update Admin)
# Exploit Title: Heatmiser Wifi Thermostat 1.7 - Cross-Site Request Forgery
Huawei E5330 21.210.09.00.158 – Cross-Site Request Forgery (Send SMS)
# Exploit Title: Huawei E5330 Cross-Site Request Forgery (Send SMS)
Huawei Router HG532e – Command Execution
#!/bin/python
Cisco RV110W – Password Disclosure / Command Execution
#!/usr/bin/env python2
ZTE ZXHN H168N – Improper Access Restrictions
[*] POC: (CVE-2018-7357 and CVE-2018-7358)
Huawei B315s-22 – Information Leak
#Product Family: LTE
TP-Link wireless router Archer C1200 – Cross-Site Scripting
[+] Unauthenticated
Rockwell Automation Allen-Bradley PowerMonitor 1000 – Incorrect Access Control Authentication Bypass
# Exploit Title: Rockwell Automation Allen-Bradley PowerMonitor 1000 - Incorrect Access Control
Rockwell Automation Allen-Bradley PowerMonitor 1000 – Cross-Site Scripting
# Exploit Title: Rockwell Automation Allen-Bradley PowerMonitor 1000 - Cross-Site Scripting
Schneider Electric PLC – Session Calculation Authentication Bypass
#!/usr/bin/env python
Zyxel VMG1312-B10D 5.13AAXA.8 – Directory Traversal
# Exploit Title: Zyxel VMG1312-B10D 5.13AAXA.8 - Directory Traversal
Ricoh myPrint 2.9.2.4 – Hard-Coded Credentials
# Exploit Title: Ricoh myPrint 2.9.2.4 - Hard-Coded Credentials
Synaccess netBooter NP-0801DU 7.4 – Cross-Site Request Forgery (Add Admin)
# Title: Synaccess netBooter NP-0801DU 7.4 - Cross-Site Request Forgery (Add Admin)
D-LINK Central WifiManager CWM-100 – Server-Side Request Forgery
# Exploit Title: D-LINK Central WifiManager CWM-100 - Server-Side Request Forgery
TP-Link Archer C50 Wireless Router 171227 – Cross-Site Request Forgery (Configuration File Disclosure)
# Exploit Title: TP-Link Archer C50 Wireless Router 171227 - Cross-Site Request Forgery (Configuration File Disclosure)
Virgin Media Hub 3.0 Router – Denial of Service (PoC)
# Exploit Title: Virgin Media Hub 3.0 Router - Denial of Service (PoC)
ZyXEL VMG3312-B10B < 1.00(AAPP.7) - Credential Disclosure
# Exploit Title: ZyXEL VMG3312-B10B - Leak Credentials < 1.00(AAPP.7)
Netgear WiFi Router R6120 – Credential Disclosure
# Exploit Title: NETGEAR WiFi Router R6120 - Credential Disclosure
TP-Link TL-SC3130 1.6.18 – RTSP Stream Disclosure
# Exploit Title: TP-Link TL-SC3130 1.6.18 - RTSP Stream Disclosure
FLIR AX8 Thermal Camera 1.32.16 – Hard-Coded Credentials
# Exploit Title: FLIR AX8 Thermal Camera 1.32.16 - Hard-Coded Credentials
Heatmiser Wifi Thermostat 1.7 – Credential Disclosure
# Exploit Title: Heatmiser Wifi Thermostat 1.7 - Credential Disclosure
FLIR Brickstream 3D+ – RTSP Stream Disclosure
FLIR Systems FLIR Brickstream 3D+ Unauthenticated RTSP Stream Disclosure
FLIR AX8 Thermal Camera 1.32.16 – RTSP Stream Disclosure
# Exploit Title: FLIR AX8 Thermal Camera 1.32.16 - RTSP Stream Disclosure
FLIR AX8 Thermal Camera 1.32.16 – Remote Code Execution
# Exploit Title: FLIR AX8 Thermal Camera 1.32.16 - Remote Code Execution