About me

Nothing to see here for now…

I’m currently focusing/learning…

  • C++ (and memory bugs)
  • Malware developement
  • DSA
  • Code review on large OSS projects (abt 100k+ SLOC)

Areas of interest

  • Low level stuff
    • OSdev, Kernel, etc
    • C, Assembly (x86 family, ARM)
    • Network protocols (and their implementations)
  • Program security
    • Binary exploitation (mainly on x86 but sometimes ARM)
    • Code review and bug hunting
    • Reverse engineering
  • Video games heh :)

Vulnerability reports

CVE-IDVendorComponentsExploit primitiveSecurity implications
CVE-2024-6044D-LinkEagle pro home routerPath traversalArbitrary file read (Network adjacent)
CVE-2024-6045D-LinkEagle pro home routerHidden functionality, Hardcoded credentialRCE (Network adjacent, Pre-auth)
CVE-2024-45694D-LinkDIR-X home routerStack-based buffer overflowRCE (Pre-auth)
CVE-2024-45695D-LinkDIR-X home routerStack-based buffer overflowRCE (Pre-auth)
CVE-2024-45696D-LinkDIR-X home routerHidden functionality, Hard-coded credentialRCE (Pre-auth)
CVE-2024-45697D-LinkDIR-X home routerMisconfigurationRCE (Pre-auth)
CVE-2024-45698D-LinkDIR-X home routerCommand injectionRCE (Authenticated)
Not assignedMongodblibbson (part of Mongodb C driver)OOB RWUnspecified (Application-specific)
CVE-2025-24302Intel open sourceTinyCBORUncontrolled recursionDenial-of-Service
CVE-2025-20025Intel open sourceTinyCBORImproper character escapingUnspecified (Application-specific)

Contact

Feel free to reach out with any feedback:

OpenPGP public keys / Finger prints: