<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Firmware — PoC Archive</title><link>https://poc.intelseclab.com/tags/firmware/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 06 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/firmware/index.xml" rel="self" type="application/rss+xml"/><item><title>XSpeeder SXZOS Pre-Auth eval() Remote Code Execution (CVE-2025-54322)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-54322-xspeeder-sxzos-preauth-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-54322-xspeeder-sxzos-preauth-rce/</guid><description>Critical severity (CVSS 10) — network · CVE-2025-54322. Status: Weaponized. Affects: XSpeeder SXZOS firmware (SD-WAN devices, routers, edge networking equipment). Tags: xspeeder, sxzos, sd-wan, router, firmware, python, django, eval-injection, pre-auth, rce, cwe-95.</description><category>network</category><category>Critical</category><category>xspeeder</category><category>sxzos</category><category>sd-wan</category><category>router</category><category>firmware</category><category>python</category><category>django</category><category>eval-injection</category><category>pre-auth</category><category>rce</category><category>cwe-95</category></item><item><title>Zyxel VMG3625-T50B Authenticated Command Injection to Root SSH Access (CVE-2026-1459)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-1459-zyxel-router-command-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-1459-zyxel-router-command-injection/</guid><description>High severity — network · CVE-2026-1459. Status: PoC. Affects: Zyxel VMG3625-T50B (and similar) router firmware. Tags: zyxel, router, firmware, command-injection, cgi-bin, ssh, authenticated, iot.</description><category>network</category><category>High</category><category>zyxel</category><category>router</category><category>firmware</category><category>command-injection</category><category>cgi-bin</category><category>ssh</category><category>authenticated</category><category>iot</category></item><item><title>ZTE ZXHN H298A / H108N Router Unauthenticated Credential Disclosure (CVE-2026-34474)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34474-zte-router-sensitive-data-exposure/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34474-zte-router-sensitive-data-exposure/</guid><description>High severity — network · CVE-2026-34474. Status: PoC. Affects: ZTE ZXHN H298A (hardware 1.1) and ZXHN H108N (hardware 2.6) home routers. Tags: information-disclosure, router, firmware, unauthenticated, credential-leak, iot, zte, wifi.</description><category>network</category><category>High</category><category>information-disclosure</category><category>router</category><category>firmware</category><category>unauthenticated</category><category>credential-leak</category><category>iot</category><category>zte</category><category>wifi</category></item><item><title>ZTE ZXHN H188A Unauthenticated Wizard Handler Credential Disclosure / Auth Bypass (CVE-2026-34472)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34472-zte-h188a-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34472-zte-h188a-auth-bypass/</guid><description>Critical severity — network · CVE-2026-34472. Status: PoC. Affects: ZTE ZXHN H188A V6 home router firmware. Tags: router, firmware, unauthenticated, auth-bypass, credential-leak, iot, zte, wifi.</description><category>network</category><category>Critical</category><category>router</category><category>firmware</category><category>unauthenticated</category><category>auth-bypass</category><category>credential-leak</category><category>iot</category><category>zte</category><category>wifi</category></item><item><title>ZTE Router Unauthenticated Oversized-POST Denial of Service (CVE-2026-34473)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34473-zte-router-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34473-zte-router-dos/</guid><description>High severity — network · CVE-2026-34473. Status: PoC. Affects: ZTE H-series routers (17+ models, reported as affecting 140K+ devices). Tags: router, firmware, unauthenticated, denial-of-service, iot, zte, cgilua, web-interface.</description><category>network</category><category>High</category><category>router</category><category>firmware</category><category>unauthenticated</category><category>denial-of-service</category><category>iot</category><category>zte</category><category>cgilua</category><category>web-interface</category></item><item><title>MIPS-Based Managed Switch Firmware Pre-Auth Kernel RCE — CVE-2026-1668</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-1668-mips-switch-kernel-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-1668-mips-switch-kernel-rce/</guid><description>Critical severity — binary · CVE-2026-1668. Status: Weaponized. Affects: MIPS-based managed switch firmware (web management HTTP server), e.g. SG2005P/SG2008/SG2016P/SG2210MP/SG2218/SG2428/SG3210/SL2428/TL-SG2428 series firmware built around 2025-10-31. Tags: mips, embedded-linux, kernel-exploit, firmware, managed-switch, reverse-shell, pre-auth, shellcode.</description><category>binary</category><category>Critical</category><category>mips</category><category>embedded-linux</category><category>kernel-exploit</category><category>firmware</category><category>managed-switch</category><category>reverse-shell</category><category>pre-auth</category><category>shellcode</category></item><item><title>Marlin Firmware M421 G-code Handler Out-of-Bounds Write — CVE-2026-56111</title><link>https://poc.intelseclab.com/pocs/hardware/2026-07-05_cve-2026-56111-marlin-m421-oob-write/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/hardware/2026-07-05_cve-2026-56111-marlin-m421-oob-write/</guid><description>High severity (CVSS 8.3) — hardware · CVE-2026-56111. Status: PoC. Affects: Marlin Firmware (3D printer firmware), builds compiled with MESH_BED_LEVELING. Tags: marlin, 3d-printer, firmware, g-code, out-of-bounds-write, mesh-bed-leveling, denial-of-service, embedded.</description><category>hardware</category><category>High</category><category>marlin</category><category>3d-printer</category><category>firmware</category><category>g-code</category><category>out-of-bounds-write</category><category>mesh-bed-leveling</category><category>denial-of-service</category><category>embedded</category></item></channel></rss>