Companies and projects I've had the chance to work with over the years
A small selection of CVEs I reported — sorted by CVSS impact. The full list is available in the CVE section.
A critical vulnerability has been identified in the Yi IOT XY-3820 (v6.0.24.10) smart camera platform, specifically within its embedded daemon process. The service, exposed on TCP port 6789, fails to properly sanitize user-supplied input, enabling remote unauthenticated attackers to execute arbitrary commands present on the file system via path traversal techniques. Successful exploitation leads to unauthorized code execution with elevated privileges.
A critical Remote Command Execution (RCE) vulnerability has been discovered in the Yi IOT XY-3820 smart camera (firmware v6.0.24.10), affecting the cmd binary. While this binary is not invoked during normal camera operation, it can be manually triggered (either locally or via another vulnerability) to spawn a root-level command server on TCP port 999. Once active, the binary listens indefinitely and processes commands sent over the network, resulting in unauthenticated, root-level code execution.
A Zip Slip vulnerability was identified in the plugin upload feature: file paths are not validated, allowing writes outside the intended directory and the upload of malicious files (webshells).
Companies that were kind enough to acknowledge my research