<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>hardware — PoC Archive</title><link>https://poc.intelseclab.com/pocs/hardware/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 06 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/pocs/hardware/index.xml" rel="self" type="application/rss+xml"/><item><title>Xiongmai XM530 IP Camera ONVIF Authentication Bypass (CVE-2025-65856)</title><link>https://poc.intelseclab.com/pocs/hardware/2026-07-06_cve-2025-65856-onvif-camera-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/hardware/2026-07-06_cve-2025-65856-onvif-camera-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — hardware · CVE-2025-65856. Status: Weaponized. Affects: Xiongmai XM530-based IP camera ONVIF service (tested on model XM530_50X50-WG_8M). Tags: xiongmai, xm530, onvif, ip-camera, iot, auth-bypass, access-control, information-disclosure, rtsp, cwe-306, cwe-287, python, bash, curl.</description><category>hardware</category><category>Critical</category><category>xiongmai</category><category>xm530</category><category>onvif</category><category>ip-camera</category><category>iot</category><category>auth-bypass</category><category>access-control</category><category>information-disclosure</category><category>rtsp</category><category>cwe-306</category><category>cwe-287</category><category>python</category><category>bash</category><category>curl</category></item><item><title>ZXIC/Sanechips ZX297520V3 BootROM Arbitrary Memory Write via USB Download Mode (CVE-2026-40003)</title><link>https://poc.intelseclab.com/pocs/hardware/2026-07-05_cve-2026-40003-zx297520v3-bootrom-memory-write/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/hardware/2026-07-05_cve-2026-40003-zx297520v3-bootrom-memory-write/</guid><description>High severity — hardware · CVE-2026-40003. Status: Weaponized. Affects: ZXIC/Sanechips ZX297520V3 SoC BootROM (used in USB modem/baseband devices). Tags: bootrom, usb-download-mode, socket-modem, zx297520v3, arbitrary-memory-write, embedded, baseband, reverse-engineering.</description><category>hardware</category><category>High</category><category>bootrom</category><category>usb-download-mode</category><category>socket-modem</category><category>zx297520v3</category><category>arbitrary-memory-write</category><category>embedded</category><category>baseband</category><category>reverse-engineering</category></item><item><title>PX4-Autopilot tattu_can Driver — CAN Bus Stack Buffer Overflow DoS (CVE-2026-32707)</title><link>https://poc.intelseclab.com/pocs/hardware/2026-07-05_cve-2026-32707-px4-tattu-can-buffer-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/hardware/2026-07-05_cve-2026-32707-px4-tattu-can-buffer-overflow/</guid><description>High severity (CVSS 7.5) — hardware · CVE-2026-32707 (GHSA-wxwm-xmx9-hr32, CWE-121). Status: PoC. Affects: PX4-Autopilot flight controller firmware, tattu_can driver. Tags: px4, autopilot, can-bus, socketcan, stack-buffer-overflow, drone, uav, denial-of-service.</description><category>hardware</category><category>High</category><category>px4</category><category>autopilot</category><category>can-bus</category><category>socketcan</category><category>stack-buffer-overflow</category><category>drone</category><category>uav</category><category>denial-of-service</category></item><item><title>PX4 Autopilot MAVLink FTP Stack Buffer Overflow (CVE-2026-32743)</title><link>https://poc.intelseclab.com/pocs/hardware/2026-07-05_cve-2026-32743-px4-mavlink-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/hardware/2026-07-05_cve-2026-32743-px4-mavlink-overflow/</guid><description>Medium severity (CVSS 6.5) — hardware · CVE-2026-32743. Status: PoC. Affects: PX4 Autopilot flight controller firmware. Tags: px4, autopilot, mavlink, drone, uav, buffer-overflow, denial-of-service, mavlink-ftp.</description><category>hardware</category><category>Medium</category><category>px4</category><category>autopilot</category><category>mavlink</category><category>drone</category><category>uav</category><category>buffer-overflow</category><category>denial-of-service</category><category>mavlink-ftp</category></item><item><title>OpenPLC_v3 glue_generator Path Traversal — CVE-2026-31156</title><link>https://poc.intelseclab.com/pocs/hardware/2026-07-05_cve-2026-31156-openplc-glue-generator-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/hardware/2026-07-05_cve-2026-31156-openplc-glue-generator-traversal/</guid><description>High severity — hardware · CVE-2026-31156. Status: PoC. Affects: OpenPLC_v3 — utils/glue_generator_src/glue_generator.cpp build/code-generation utility. Tags: openplc, ics, path-traversal, arbitrary-file-write, glue-generator, cpp, plc, industrial-control.</description><category>hardware</category><category>High</category><category>openplc</category><category>ics</category><category>path-traversal</category><category>arbitrary-file-write</category><category>glue-generator</category><category>cpp</category><category>plc</category><category>industrial-control</category></item><item><title>Marlin Firmware M421 G-code Handler Out-of-Bounds Write — CVE-2026-56111</title><link>https://poc.intelseclab.com/pocs/hardware/2026-07-05_cve-2026-56111-marlin-m421-oob-write/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/hardware/2026-07-05_cve-2026-56111-marlin-m421-oob-write/</guid><description>High severity (CVSS 8.3) — hardware · CVE-2026-56111. Status: PoC. Affects: Marlin Firmware (3D printer firmware), builds compiled with MESH_BED_LEVELING. Tags: marlin, 3d-printer, firmware, g-code, out-of-bounds-write, mesh-bed-leveling, denial-of-service, embedded.</description><category>hardware</category><category>High</category><category>marlin</category><category>3d-printer</category><category>firmware</category><category>g-code</category><category>out-of-bounds-write</category><category>mesh-bed-leveling</category><category>denial-of-service</category><category>embedded</category></item></channel></rss>