rainpwn

    /work  Engagements

    Work with me.

    I test network security appliances for the people who build them: firewalls, access points, security routers, and the firmware underneath. 20 of my findings are assigned CVEs on shipped hardware, and 3 vendors have published an advisory for this work.

    Currently accepting a limited number of engagements.

    CVEs assigned
    20
    with a vendor advisory
    20/20
    median days to advisory
    67

    01  Scope

    What I look at.

    The published work is almost entirely network security appliances. I start at the web management interface, because that is what is exposed, then follow the same request into the CLI and the shell behind it, the services the box runs as root, and the firmware image once a binary is worth unpacking.

    What comes out of that is command injection, authentication bypass, privilege escalation, and file operations that were never meant to reach the filesystem. 20 of the 20 CVEs are patched and public, so you can read the work before you decide.

    It is not one vendor. The 20 identifiers are all on the same appliance family, and 2 further advisories are published and fixed on unrelated systems, with no identifier assigned yet. That is why they are named below and counted nowhere.

    Devices
    Firewalls, APs, security routers
    Layers
    Web UI, CLI, services, firmware
    Languages
    English, Italian
    Team
    Alone, or with Hackerhood

    02  Setup

    You do not have to ship hardware.

    Hardware

    You send the appliance and I put it on the bench with a serial console attached. All 19 CVEs came from a device I could physically open.

    Firmware image

    Sometimes the box cannot leave the building, or has not been built yet. Then I work from the image. I unpack it and run what I can under emulation, and I miss anything that only breaks on real silicon.

    Remote lab

    You stand up an instance and give me access. I lose the serial console and most of the firmware layer, so it turns up less than the other two. When the device cannot leave your network it is the only way in.

    Patch verification

    This one comes after a report instead of before it: you have written a fix, and I try to get around it. It is the shortest of the four.

    We agree the scope and the time before anything starts. I work on one device at a time and go all the way down on it, so a list of twelve products with a two-week deadline is not something I can do well.

    03  Deliverable

    You already know what the report looks like.

    Most people who do this work cannot show you a report, because every report they have written is under NDA. The writeups on this site are the public half of the same document: the reproduction steps, the affected versions, the exact request, the code path, and the disclosure timeline down to the day.

    What a private report adds is what a public one has to leave out. Findings that never became a CVE, the ones that need two other things to be true first, the notes on what was tried and did not work, and a retest once you have written the fix.

    04  Disclosure

    What happens to what I find.

    Under NDA, nothing is published. Outside one, the vendor is notified first and nothing goes out before a fix is available. The site publishes 11 disclosure timelines with the dates on them, so you can check how that went every time.

    • The vendor sets the publication date, not me.

      Four times a vendor asked to postpone a public disclosure. Four times I waited. The longest hold was CVE-2025-11730, reported on 10 September 2025 and published on 5 February 2026, 148 days.

      CVE-2025-11730
    • A fix that does not fix it gets reported again.

      The Configuration Migration Tool was patched in August 2022. I applied the patch, found the file deletion still worked, and reported it again. The second fix shipped in September.

      ZYXEL CMT
    • When your engineers cannot reproduce it, I work with them.

      The vendor's product team could not reproduce the token impersonation for two weeks. I asked to be put in touch with the RD team directly, walked them through it, and they reproduced it the same day.

      CVE-2025-1731
    • Not everything needs to become a CVE.

      A prompt injection in the Nebula AI assistant was reported on 11 September 2025 and fixed on the 12th. No identifier, no advisory, no publication until it was closed.

      Nebula AI

    05  Start

    What to put in the first email.

    An email is enough to start. Four lines tell me whether I am the right person, and roughly how long it would take.

    1. 01The device or the firmware, with the version.
    2. 02Whether you can ship hardware, or not.
    3. 03What you are worried about, if anything specific.
    4. 04When you need it by.

    If you want to send me something securely, use the PGP key. It is on the contact page.