Sunday, September 27, 2026

Auditing routers, cameras and OT gear with EmbedXPL-Forge

Auditing routers, cameras and OT gear with EmbedXPL-Forge

EmbedXPL-Forge is a Python exploitation and scanning framework for authorized audits of routers, IP cameras, printers, GPON ONTs and OT devices across 114+ vendors.

Toolmrhenrike/EmbedXPL-Forge — Python exploitation and scanning framework for embedded and perimeter devices, v3.2.0
CategoryExploitation/assessment framework (Python, ~42 stars)
Primary UseAuthorized auditing of routers, IP cameras, NVRs, printers, NAS, VPN appliances and ICS devices using 2800+ modules mapped to 700+ CVEs
Safe UseUse only in authorized penetration tests, lab environments, or against devices you own; the framework's credential testing and exploit modules must never target third-party infrastructure
Telemetry NoteModules generate conspicuous network activity — ARP sweeps, nmap/masscan scans, RTSP brute-force attempts, and dictionary attacks against FTP/SSH/Telnet/HTTP/SNMP — all of which are visible to IDS/IPS and authentication logging on monitored networks

EmbedXPL-Forge bills itself as an embedded and perimeter security assessment framework, and the scale of the README makes clear this is not a niche script collection. Version 3.2.0 claims 2800+ active modules spanning routers, switches, IP cameras, NVR/DVR units, GPON ONTs, ISP CPEs, printers, NAS devices, VPN/firewall appliances, IoT and OT/ICS targets, with 700+ CVEs mapped across 114+ vendors. The project is written in Python 3.8+, developed primarily on Linux — Debian, Ubuntu and Kali — with an explicit platform note that most hardware-dependent modules involving wireless adapters, USB devices, raw sockets and firmware tooling require Linux for full functionality.

Architecturally, the framework follows the familiar Metasploit-style console pattern that most operators will recognize immediately. The interactive shell drops you into an exf > prompt where use <module> selects a module, show options and show info expose configuration and metadata, check performs a non-destructive vulnerability verification, and run executes it. There is also direct single-module invocation from the shell, network-wide discovery via discover <subnet> with T0-T5 timing profiles, and persistent session management keyed per host by IP and MAC address so long engagements can be resumed rather than restarted.

The discovery pipeline is worth noting because it shows deliberate engineering rather than a thin wrapper. Discovery runs a multi-phase sweep: ARP discovery first, then nmap with multi-method host probes, a Scapy fallback, and finally a plain TCP connect scan if the earlier methods fail. Results are fingerprinted and matched against the module database, so the framework can suggest candidate modules per discovered device — an autopwn-adjacent workflow, but one where the operator retains the decision of what actually runs. OUI lookups against an IEEE database of 39k+ entries help identify vendors during fingerprinting.

Module coverage is unusually broad. There are 625+ exploit modules covering RCE, authentication bypass, path traversal, info disclosure, buffer overflows, DNS hijacking, command injection, CSRF, configuration decryption and WPA/WPS keygen behavior; 88 credential modules performing dictionary attacks against FTP, SSH, Telnet, HTTP, SNMP and SFTP; a 185+ module printer arsenal spanning HP, Canon, Lexmark, Xerox, Ricoh, Brother, Epson, Kyocera and Samsung over PJL, IPP, LPD, WSD and CUPS; and a dedicated RTSP camera engine with brute-force against 195+ routes and 80+ credential pairs, RTSPS/TLS support, ONVIF WS-Discovery and a pure-Python RTSP-over-HTTP tunnel implementing RFC 2326 Appendix C.

The RTSP engine is complemented by seven custom nmap NSE scripts shipped as an optional extra — installable via pip install "embedxpl[nse]" and then embedxpl-nse install — covering RTSP discovery, camera fingerprinting, Hikvision and Dahua CVE validation, default credential testing and multi-vendor checks. This is a sensible design choice: NSE scripts integrate into existing nmap-driven reconnaissance workflows, letting teams use EmbedXPL-Forge's detection logic without adopting its console as their primary interface. Note the README's caution that installing into /usr/share/nmap/scripts/ typically requires sudo.

Two features stand out as differentiators from typical RouterSploit-style forks. The first is the PolyExploit orchestrator, which handles runtime compilation of C/C++ exploits via gcc, clang and mingw cross-compilers, executes exploits written in Ruby, Node.js, PHP, Bash and Perl, and integrates with msfconsole and searchsploit. The second is the APT Group Attack Engine, which catalogs reproducible attack chains attributed to groups like APT28, Volt Typhoon, Sandworm, Quad7, Turla and APT40, each with MITRE ATT&CK mapping. From a defensive standpoint this engine is arguably most valuable as a purple-team resource: apt show <group> reveals which CVEs and device classes each actor historically targeted, which is directly useful for prioritizing patch effort on perimeter appliances.

The ICS/OT coverage adds 35+ modules touching Modbus, S7comm, EtherNet/IP, BACnet, DNP3, PROFINET DCP, Universal Robots PolyScope 5, OpenPLC, RIOT OS and VxWorks/QNX targets, plus niche categories like smart home (eNet SMART HOME, OpenRemote) and maritime IoT (Metis WIC/DFS). The VPN and firewall appliance category is the largest single block at 202 modules, covering Palo Alto PAN-OS, Fortinet FortiOS, Cisco ASA/FTD, Ivanti, Juniper, SonicWall, pfSense and many more — a reminder that perimeter devices remain the most targeted class of network infrastructure.

Quality control is addressed explicitly: seven automated gates enforced by tools/phase_gate.py require every module to pass import checks, anti-false-positive checks, reference validation and code quality checks before merge. For a framework this large, that gating is the difference between a usable corpus and a graveyard of broken modules, and it signals the maintainer is investing in maintainability rather than raw module count alone. The vendor wordlists — 23+ sets of default credentials externalized per vendor, including ISP-specific Brazilian lists — follow the same externalized-data philosophy, keeping credentials out of module code.

Installation is straightforward: pip install embedxpl and launch embedxpl, or clone from source and run ./setup_venv.sh followed by ./run.sh, which the README notes is PEP 668-safe on modern Debian-family distributions. The licensing badge claims MIT while GitHub reports NOASSERTION, so teams intending to embed it in commercial engagements should verify the LICENSE file directly. Operationally, this framework is loud by design — every module that touches a target produces authentication failures, scan traffic and service anomalies that a competent SOC will see. That is exactly the point: EmbedXPL-Forge belongs in authorized engagements, lab ranges and device-security research, where its breadth and APT chain catalog can be put to documented, consented use.

Official project repository for mrhenrike/EmbedXPL-Forge.
Download Tool

Educational analysis for authorized security professionals. Use only in controlled, authorized environments.

Share articleFacebookXLinkedIn

Continue exploring

Browse all articles →

0 comentários:

Post a Comment

Note: Only a member of this blog may post a comment.