Cisco243 CVE-2026-20093: Unauthenticated Admin Reset on Cisco IMC
CVE-2026-20093 is a CVSS 9.8 pre-auth password change on Cisco IMC via configConfMo/aaaUser. Lab notes unpack HUU 4.3.2.250063 vs 4.3.2.260007: nginx /nuova,…
Cisco243 CVE-2026-20093 is a CVSS 9.8 pre-auth password change on Cisco IMC via configConfMo/aaaUser. Lab notes unpack HUU 4.3.2.250063 vs 4.3.2.260007: nginx /nuova,…
Cisco202 Aaron Thacker jailbroke a Cisco C195 ESA by splicing a newer BIOS so CIMC came online, exploiting command injection in expRemoteFwUpdate (CVE-2024-20356)…
Exploit Development430 Every hardware security boundary on a modern x86 platform — SMRAM, the AMD PSP's private DRAM, the C6 save area, the live…
buffer overflow397 A complete hardware-to-firmware walkthrough of the Mercusys MB115-4G, the best-selling router on Amazon Spain: pre-purchase firmware recon, PCB teardown, UART pinout discovery…
Debug327 A first-principles deep-dive into dumping, analyzing, and patching hard drive firmware: Western Digital custom LZHUF decompression, Samsung SSD deobfuscation, JTAG debugging of…
Apple Silicon357 Apple Silicon's chain of trust hands the XNU kernel an SMMU/IOMMU configuration that iBoot builds once and the OS never re-verifies. An…
Cybersecurity236 A deep dive into CVE-2021-21735 on the ZTE ZXHN H168N home gateway, where two unauthenticated wizard endpoints (wizard_pppoe_lua.lua and wizard_wlan_config_lua.lua) leaked PPPoE…
Camera230 Researchers exploited weaknesses in Xiaomi’s miIO protocol to bypass authentication, predict cryptographic values, and trigger memory corruption, ultimately achieving remote code execution…
Bluetooth224 Bloodied (but not broken) by the ordeal, I achieved my goals and stretch goals. And given that there are no public descriptions…
BIOS247 The article shows how modifying UEFI firmware at the flash level can disable BIOS security features even when the interface is locked,…
Embedded198 Researchers discovered CVE-2026-0714 where a Moxa embedded device leaks its LUKS disk key in plaintext over the TPM SPI bus during boot.…
AI Agents180 The article shows how AI-assisted reverse engineering of the TP-Link Tapo C200 firmware uncovered hardcoded keys, buffer overflows, and insecure APIs, demonstrating…