Vulnerabilities I found and reported, with write-ups and PoCs. Each directory is one CVE.
Our team CoreSecurity in Republic of Korea. (coresec@coresec.co.kr)
finding bugs in OT/ICS Area
Member: 홍승표(Ph4nt0m), 배대식(pinebudweiser), 임은서(Turtle3), 조이수(isj), 배정훈(rhenus)
Leader: 윤민규(mkyoon)
| CVE | Target | Bug type |
|---|---|---|
| CVE-2024-33788 | Linksys E5600 | Command Injection |
| CVE-2024-33789 | Linksys E5600 | Command Injection |
| CVE-2024-33791 | netis MEX605 | Cross Site Scripting |
| CVE-2024-33792 | netis MEX605 | Command Injection |
| CVE-2024-33793 | netis MEX605 | Command Injection |
| CVE-2025-55423 | ipTIME routers (163 models) | Command Injection |
project team in BoB(a.k.a Best of the Best) in Republic of Korea. (bobfuzzer@gmail.com)
finding bugs in linux kernel filesystem modules
Project Member: 김동희(Kieast), 조형진(zkaryaJo), 홍승표(Ph4nt0m), 남지효(NJhyo), 정원영(nonetype)
Project Leader: 조성준(DelspoN)
Project Mentor: 이상섭(k1rh4), 박천성(Ashine)
CVE-2019-18885, CVE-2019-19036, CVE-2019-19037, CVE-2019-19039, CVE-2019-19318, CVE-2019-19319, CVE-2019-19377, CVE-2019-19378, CVE-2019-19447, CVE-2019-19448, CVE-2019-19449, CVE-2019-19813, CVE-2019-19814, CVE-2019-19815, CVE-2019-19816, CVE-2019-19927
This Project used ported version(to 5.0.21 and 5.3.14 linux kernel) of filesystem fuzzer 'JANUS' which developed by GeorgiaTech Systems Software & Security Lab(SSLab)
Thank you for the excellent fuzzer and paper below.