<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Iot — PoC Archive</title><link>https://poc.intelseclab.com/tags/iot/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 11 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/iot/index.xml" rel="self" type="application/rss+xml"/><item><title>D-Link DIR-820L `get_set.ccp` LAN Configuration OS Command Injection (CVE-2022-26258)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-11_cve-2022-26258-dlink-dir820l-command-injection/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-11_cve-2022-26258-dlink-dir820l-command-injection/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2022-26258. Status: Weaponized (public PoC available; listed in CISA KEV). Affects: D-Link DIR-820L wireless router, all hardware revisions. Tags: d-link, dir-820l, router, command-injection, cwe-78, unauthenticated, remote, iot, eol-device, kev.</description><category>network</category><category>Critical</category><category>d-link</category><category>dir-820l</category><category>router</category><category>command-injection</category><category>cwe-78</category><category>unauthenticated</category><category>remote</category><category>iot</category><category>eol-device</category><category>kev</category></item><item><title>Xiongmai XM530 IP Camera ONVIF Authentication Bypass (CVE-2025-65856)</title><link>https://poc.intelseclab.com/pocs/hardware/2026-07-06_cve-2025-65856-onvif-camera-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/hardware/2026-07-06_cve-2025-65856-onvif-camera-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — hardware · CVE-2025-65856. Status: Weaponized. Affects: Xiongmai XM530-based IP camera ONVIF service (tested on model XM530_50X50-WG_8M). Tags: xiongmai, xm530, onvif, ip-camera, iot, auth-bypass, access-control, information-disclosure, rtsp, cwe-306, cwe-287, python, bash, curl.</description><category>hardware</category><category>Critical</category><category>xiongmai</category><category>xm530</category><category>onvif</category><category>ip-camera</category><category>iot</category><category>auth-bypass</category><category>access-control</category><category>information-disclosure</category><category>rtsp</category><category>cwe-306</category><category>cwe-287</category><category>python</category><category>bash</category><category>curl</category></item><item><title>ThingsBoard IoT Platform SSRF via SVG Image Upload (CVE-2025-34282)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-34282-thingsboard-ssrf-svg-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-34282-thingsboard-ssrf-svg-upload/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2025-34282. Status: Weaponized. Affects: ThingsBoard IoT Platform (Image Upload Gallery / Widget Library). Tags: thingsboard, ssrf, cwe-918, svg, image-upload, iot, python, widget-library, tenant-admin.</description><category>web</category><category>Critical</category><category>thingsboard</category><category>ssrf</category><category>cwe-918</category><category>svg</category><category>image-upload</category><category>iot</category><category>python</category><category>widget-library</category><category>tenant-admin</category></item><item><title>Tenda AC9 `AdvSetMacMtuWan` Stack-Based Buffer Overflow (CVE-2025-29384)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-29384-tenda-ac9-stack-overflow/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-29384-tenda-ac9-stack-overflow/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-29384. Status: PoC. Affects: Tenda AC9 dual-band wireless router, web management interface (/goform/AdvSetMacMtuWan endpoint). Tags: tenda, ac9, router, stack-buffer-overflow, cwe-121, dos, rce, mips, embedded, iot, python, ruby, metasploit.</description><category>network</category><category>Critical</category><category>tenda</category><category>ac9</category><category>router</category><category>stack-buffer-overflow</category><category>cwe-121</category><category>dos</category><category>rce</category><category>mips</category><category>embedded</category><category>iot</category><category>python</category><category>ruby</category><category>metasploit</category></item><item><title>D-Link AX1500 SetDeviceSettings `DeviceName` OS Command Injection (CVE-2025-60854)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-60854-dlink-ax1500-devicename-command-injection/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-60854-dlink-ax1500-devicename-command-injection/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-60854. Status: Weaponized. Affects: D-Link AX1500 router firmware (HNAP/DHMAPI web management SOAP interface). Tags: d-link, ax1500, router, command-injection, os-command-injection, hnap, soap, telnetd, cwe-78, iot.</description><category>network</category><category>Critical</category><category>d-link</category><category>ax1500</category><category>router</category><category>command-injection</category><category>os-command-injection</category><category>hnap</category><category>soap</category><category>telnetd</category><category>cwe-78</category><category>iot</category></item><item><title>Zyxel VMG3625-T50B Authenticated Command Injection to Root SSH Access (CVE-2026-1459)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-1459-zyxel-router-command-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-1459-zyxel-router-command-injection/</guid><description>High severity — network · CVE-2026-1459. Status: PoC. Affects: Zyxel VMG3625-T50B (and similar) router firmware. Tags: zyxel, router, firmware, command-injection, cgi-bin, ssh, authenticated, iot.</description><category>network</category><category>High</category><category>zyxel</category><category>router</category><category>firmware</category><category>command-injection</category><category>cgi-bin</category><category>ssh</category><category>authenticated</category><category>iot</category></item><item><title>ZTE ZXHN H298A / H108N Router Unauthenticated Credential Disclosure (CVE-2026-34474)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34474-zte-router-sensitive-data-exposure/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34474-zte-router-sensitive-data-exposure/</guid><description>High severity — network · CVE-2026-34474. Status: PoC. Affects: ZTE ZXHN H298A (hardware 1.1) and ZXHN H108N (hardware 2.6) home routers. Tags: information-disclosure, router, firmware, unauthenticated, credential-leak, iot, zte, wifi.</description><category>network</category><category>High</category><category>information-disclosure</category><category>router</category><category>firmware</category><category>unauthenticated</category><category>credential-leak</category><category>iot</category><category>zte</category><category>wifi</category></item><item><title>ZTE ZXHN H188A Unauthenticated Wizard Handler Credential Disclosure / Auth Bypass (CVE-2026-34472)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34472-zte-h188a-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34472-zte-h188a-auth-bypass/</guid><description>Critical severity — network · CVE-2026-34472. Status: PoC. Affects: ZTE ZXHN H188A V6 home router firmware. Tags: router, firmware, unauthenticated, auth-bypass, credential-leak, iot, zte, wifi.</description><category>network</category><category>Critical</category><category>router</category><category>firmware</category><category>unauthenticated</category><category>auth-bypass</category><category>credential-leak</category><category>iot</category><category>zte</category><category>wifi</category></item><item><title>ZTE Router Unauthenticated Oversized-POST Denial of Service (CVE-2026-34473)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34473-zte-router-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34473-zte-router-dos/</guid><description>High severity — network · CVE-2026-34473. Status: PoC. Affects: ZTE H-series routers (17+ models, reported as affecting 140K+ devices). Tags: router, firmware, unauthenticated, denial-of-service, iot, zte, cgilua, web-interface.</description><category>network</category><category>High</category><category>router</category><category>firmware</category><category>unauthenticated</category><category>denial-of-service</category><category>iot</category><category>zte</category><category>cgilua</category><category>web-interface</category></item><item><title>Wyze Cam Pan v3 / TUTK SDK — tutk_packet_alloc Heap Overflow (CVE-2026-38698)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-38698-wyze-cam-tutk-heap-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-38698-wyze-cam-tutk-heap-overflow/</guid><description>Critical severity — network · CVE-2026-38698. Status: PoC. Affects: TUTK SDK (as used in Wyze Cam Pan v3 and other TUTK-based IoT cameras). Tags: tutk-sdk, iot, camera, heap-overflow, av-server, wyze, authenticated, p2p.</description><category>network</category><category>Critical</category><category>tutk-sdk</category><category>iot</category><category>camera</category><category>heap-overflow</category><category>av-server</category><category>wyze</category><category>authenticated</category><category>p2p</category></item><item><title>TP-Link Tapo C260 Unauthenticated-to-Root RCE Chain — CVE-2026-0651</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-0651-tapo-c260-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-0651-tapo-c260-rce/</guid><description>Critical severity — network · CVE-2026-0651 (chained with CVE-2026-0652, CVE-2026-0653). Status: Weaponized. Affects: TP-Link Tapo C260 IP camera (pre-patch firmware, shared /bin/main omnibus binary across models). Tags: iot, ip-camera, tp-link, tapo, path-traversal, command-injection, privilege-escalation, exploit-chain.</description><category>network</category><category>Critical</category><category>iot</category><category>ip-camera</category><category>tp-link</category><category>tapo</category><category>path-traversal</category><category>command-injection</category><category>privilege-escalation</category><category>exploit-chain</category></item><item><title>TP-Link DHCP Option 66 Unauthenticated RCE — CVE-2026-11834</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-11834-tplink-dhcp-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-11834-tplink-dhcp-rce/</guid><description>Critical severity — network · CVE-2026-11834. Status: Weaponized. Affects: TP-Link router firmware (libcmm.so DHCP client), tested on Archer C20 V6. Tags: tp-link, router, dhcp, command-injection, cwe-78, race-condition, rce, iot.</description><category>network</category><category>Critical</category><category>tp-link</category><category>router</category><category>dhcp</category><category>command-injection</category><category>cwe-78</category><category>race-condition</category><category>rce</category><category>iot</category></item><item><title>TP-Link Archer C64 Web UI Rate-Limit Bypass via Residual Debug SSH Service (CVE-2026-8697)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-8697-tplink-archer-c64-ssh-ratelimit-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-8697-tplink-archer-c64-ssh-ratelimit-bypass/</guid><description>Critical severity (CVSS 9.3) — network · CVE-2026-8697. Status: PoC. Affects: TP-Link Archer C64 router firmware ("TPOS"). Tags: tplink, archer-c64, router, ssh, rate-limit-bypass, authentication-oracle, brute-force, iot.</description><category>network</category><category>Critical</category><category>tplink</category><category>archer-c64</category><category>router</category><category>ssh</category><category>rate-limit-bypass</category><category>authentication-oracle</category><category>brute-force</category><category>iot</category></item><item><title>Tenda HG7/HG9/HG10 Router Stack-Based Buffer Overflow — CVE-2026-11499</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-11499-tenda-router-bof/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-11499-tenda-router-bof/</guid><description>High severity — network · CVE-2026-11499. Status: PoC. Affects: Tenda HG7 / HG9 / HG10 routers (firmware family HG7_HG9_HG10re_300001138_en_xpon and similar). Tags: tenda, router, buffer-overflow, cwe-121, dos, embedded, iot, rce.</description><category>network</category><category>High</category><category>tenda</category><category>router</category><category>buffer-overflow</category><category>cwe-121</category><category>dos</category><category>embedded</category><category>iot</category><category>rce</category></item><item><title>Tasmota fetch_jpg() strcpy() Buffer Overflow in boundary[40] (CVE-2026-38426)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-38426-tasmota-fetchjpg-strcpy-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-38426-tasmota-fetchjpg-strcpy-overflow/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-38426. Status: PoC. Affects: Arendst Tasmota (ESP32 firmware). Tags: tasmota, esp32, iot, buffer-overflow, strcpy, rce, mjpeg, scripter.</description><category>network</category><category>Critical</category><category>tasmota</category><category>esp32</category><category>iot</category><category>buffer-overflow</category><category>strcpy</category><category>rce</category><category>mjpeg</category><category>scripter</category></item><item><title>Tasmota fetch_jpg() Integer Wraparound to Heap Corruption (CVE-2026-38427)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-38427-tasmota-fetchjpg-integer-wraparound/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-38427-tasmota-fetchjpg-integer-wraparound/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-38427. Status: PoC. Affects: Arendst Tasmota (ESP32 firmware). Tags: tasmota, esp32, iot, integer-overflow, heap-corruption, rce, mjpeg, scripter.</description><category>network</category><category>Critical</category><category>tasmota</category><category>esp32</category><category>iot</category><category>integer-overflow</category><category>heap-corruption</category><category>rce</category><category>mjpeg</category><category>scripter</category></item><item><title>Tasmota fetch_jpg() Combined Buffer Overflow RCE Chain (CVE-2026-38422)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-38422-tasmota-fetchjpg-combined-overflow-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-38422-tasmota-fetchjpg-combined-overflow-rce/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-38422. Status: PoC. Affects: Arendst Tasmota (ESP32 firmware). Tags: tasmota, esp32, iot, buffer-overflow, integer-overflow, rce, mjpeg, scripter.</description><category>network</category><category>Critical</category><category>tasmota</category><category>esp32</category><category>iot</category><category>buffer-overflow</category><category>integer-overflow</category><category>rce</category><category>mjpeg</category><category>scripter</category></item><item><title>OpenRemote — Expression Injection RCE in Rules Engine (CVE-2026-39842)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39842-openremote-expression-injection-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39842-openremote-expression-injection-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-39842 / GHSA-7mqr-33rv-p3mp. Status: Weaponized. Affects: OpenRemote (IoT device/rules management platform). Tags: openremote, iot, nashorn, javascript-injection, rules-engine, rce, authenticated, root.</description><category>web</category><category>Critical</category><category>openremote</category><category>iot</category><category>nashorn</category><category>javascript-injection</category><category>rules-engine</category><category>rce</category><category>authenticated</category><category>root</category></item><item><title>MR9600 Router Bluetooth/JNAP Management Interface RCE Injection (CVE-2026-6992)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-6992-mr9600-router-bluetooth-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-6992-mr9600-router-bluetooth-rce/</guid><description>High severity — network · CVE-2026-6992. Status: PoC. Affects: MR9600 router (Bluetooth-capable administrative interface). Tags: router, bluetooth, jnap, command-injection, iot, rce.</description><category>network</category><category>High</category><category>router</category><category>bluetooth</category><category>jnap</category><category>command-injection</category><category>iot</category><category>rce</category></item><item><title>GeoVision GV-I/O Box 4E DVRSearch Unauthenticated Stack Buffer Overflow RCE (CVE-2026-12485)</title><link>https://poc.intelseclab.com/pocs/network/2026-06-30_cve-2026-12485-geovision-dvrsearch-rce/</link><pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-06-30_cve-2026-12485-geovision-dvrsearch-rce/</guid><description>Critical severity (CVSS 10) — network · CVE-2026-12485. Status: PoC. Affects: GeoVision GV-I/O Box 4E (Linux-based smart embedded I/O device). Tags: RCE, unauthenticated, stack-overflow, buffer-overflow, IoT, GeoVision, DVR, embedded, UDP, network, Python, CVSS-10.</description><category>network</category><category>Critical</category><category>RCE</category><category>unauthenticated</category><category>stack-overflow</category><category>buffer-overflow</category><category>IoT</category><category>GeoVision</category><category>DVR</category><category>embedded</category><category>UDP</category><category>network</category><category>Python</category><category>CVSS-10</category></item></channel></rss>