RSSAmplifier

Blog

Stig's Lab Notes

A blog focused on vulnerability research, exploit development and general security topics.

stigward.github.ioRSS feed ↗8 posts

Latest posts

A Silly Satellite Wi-Fi Router Bug - Redport Pre-Auth RCE

Pre-auth RCE over LAN in the RedPort wXa-223 satellite Wi-Fi router, found within minutes of unpacking the firmware.

AI-Driven Binary Analysis on a TOTOLINK Router - Shooting Bugs-In-A-Barrel

Using PRIZM ZERO's AI-driven binary analysis to reproduce known CVEs and find new memory-corruption bugs in a TOTOLINK router's cstecgi.cgi.

Uncovering a 0-Click RCE in the SuperNote Nomad E-ink Tablet

Chaining a vulnerability and misconfigurations into a remotely installable, 0-click rootkit on the SuperNote Nomad E-ink tablet (CVE-2025-32409).

Rooting the FiiO M6 - Part 2 - Writing an LPE Exploit For Our Overflow Bug

Turning the FiiO M6 kernel stack overflow into a working local privilege escalation exploit.

Rooting the FiiO M6 - Part 1 - Using the "World's Worst Fuzzer" To Find A Kernel Bug

Using the world's worst fuzzer to find a kernel stack overflow in the FiiO M6's procfs debug interface.

UAF and House Of Force Fun - ROMHack CTF Swordmaster Pwn Challenge

A format string leak, a UAF heap leak, and a House of Force attack to pop a shell in the ROMHack CTF Swordmaster pwn challenge.

Wavlink Command Injection - CVE-2022-23900

An unauthenticated command injection in the Wavlink WL-WN531P3 router API, exploitable from the internet via CSRF.

JWT Confusion and SSTI - CyberSanta CTF Naughty or Nice Web Challenge

Exploiting a JWT verification flaw and an SSTI vulnerability to get RCE in the CyberSanta CTF Naughty or Nice web challenge.