Repo full of ComFast, Totolink, D-Link, and Netgear PoC exploits.
today's bounty:
today's bounty:
Repo full of ComFast, Totolink, D-Link, and Netgear PoC exploits.
D-Link /boafrm/formDateReboot submit-url buffer overflow.
D-Link /boafrm/formVpnConfigSetup submit-url parameter buffer overflow
https://www.cve.org/CVERecord?id=CVE-2026-2961
Note: the actual link to the github issue is dead. Irritating, but the vuldb link confirms its the submit-url parameter that's vulnerable.
D-Link SSDP "ST" header command injection. #internetofshit
https://www.cve.org/CVERecord?id=CVE-2026-3485
Note: This vuln is exactly the same as CVE-2025-10629 before it... Just different hardware.
@xandru Youtube says "Please sign in to prove you're not a bot."
This was outside of my threat model.
(because I am not dumb enough to have a smart vacuum)
https://www.popsci.com/technology/robot-vacuum-army/
internet of shit meets genAI