Upload Security
Blog
Firmware teardowns, vulnerability research, and plain-language briefings from the work we do.
All articles
4 published
-
24 Aug 2026
Technical write-up
CVE-2026-16348 TP-Link Archer BE800 Authenticated RCE via VPN Key Injection
Authenticated RCE as root on the TP-Link Archer BE800: a VPN key allow-list regex expressed as an ASCII range inadvertently permits the full POSIX command-substitution...
Read → -
24 Aug 2026
Technical write-up
CVE-2026-9254 TP-Link Archer BE800 Unauthenticated LAN RCE
Unauthenticated LAN RCE as root on the TP-Link Archer BE800: a parental-control deny-list omits the newline character, turning a notification API into command execution.
Read → -
6 Aug 2026
Technical write-up
Reverse Engineering Wyze Cam Pan v3: A Deep Dive into IoT Firmware Security
An in-depth analysis of WiFi credential storage mechanisms in consumer IoT firmware from initial static analysis through physical extraction and cryptographic verifica...
Read → -
6 Aug 2026
Briefing
The Hidden Risk on Your Network: Why Default SNMP Settings Are Leaking Your Secrets
How a 30-year-old network protocol might be broadcasting your confidential documents to anyone who asks
Read →