Afnaan's Research Archive
A dedicated archive of systematic research, focusing on responsible disclosure and the identification of
critical vulnerabilities.
This repository documents my CVE research, offensive security toolkits, and architectural deep-dives.
Everything here serves as an educational and ethical blueprint for building a more resilient,
secure-by-design ecosystem.
CVE Disclosure
A critical security vulnerability affecting 100+ educational institutions across India.
Discovered through independent research, the vulnerability was responsibly reported and
coordinated through CERT/CC, resulting in an official CVE
assignment with a CVSS score of 9.8 (Critical).
The vulnerability exposed sensitive data and systems across the affected institutions. Following
responsible disclosure protocols, remediation was supported before public disclosure.
9.8
CVSS Score
100+
institutions
1M+
Student's data
Projects
Raspberry Pi Pico HID Attack
The Raspberry Pi Pico acts like a keyboard and delivers malicious payload when this programmed with this script.
This script is powered by MicroPython and Adafruit library.
Project Overhaul
Project Overhaul integrates a variety of popular penetration testing tools into a single Command Line Interface.
The following tools are supported as of now:
Nmap, Netcat, Gobuster, Amass, Metasploit, Sqlmap, Hashcat, John the Ripper.
Nmap Command Generator
Python script that simplifies the process of generating Nmap commands by allowing users to
input their desired command and switches, resulting in a ready-to-use Nmap command for
network scanning.
It provides a user-friendly interface for quickly creating customized Nmap
scans.