Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

22 Commits
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Language: English · 简体中文

About

I research vulnerabilities in the Linux kernel, embedded systems, and network appliances. My work spans source auditing, fuzzing, exploit development, and responsible disclosure.

CTF player with FlappyPig and r3kapig.

106 public CVEs across 12 ecosystems, including 67 Linux kernel findings.

Selected research

Focus

  • Surfaces — Linux kernel, embedded devices, IoT, and network appliances
  • Methods — source auditing, fuzzing, reverse engineering, and exploit development
  • Practice — PWN, CTF, root-cause analysis, and responsible disclosure

Recognition

  • 2025 · 1st place — 0x300 · Tianwang Cup ITAI Critical Product Vulnerability Discovery Challenge
  • 2024 · Two 1st-place finishes — 0x300 · Tianwang Cup ITAI Critical Product Vulnerability Discovery Challenge · Matrix Cup Hardware & Software Security Testing Competition
  • 2023 · Champion — 跃哥我真不会啊 · Datacon Vulnerability Analysis Track
    2nd place — 0x300 · CSST Tianwang Cup
Earlier recognition · 2018–2021
  • 2021 · 2nd place — 0x300 · Inaugural ITAI Critical Product Security Challenge
    Best Vulnerability Reproduction — Tianfu Cup · Docker Escape & Ubuntu LPE
  • 2019 — Chaitin · GeekPwn & HUAWEI Smart Device Security Challenge · MAXHUB Exploit
  • 2018 · Best Demo Award — Piggy mine · GeekPwn

Publications

  • CTF Training Camp: Technical Deep Dives, Problem-Solving Methods, and Competition SkillsAuthor
  • Fuzzing Against the Machine
    Automate vulnerability research with emulated IoT devices on QEMUTranslator

Disclosure archive

The archive below is synchronized from bestwing.me every week.

Browse the complete CVE index · grouped by vendor

HUAWEI: CVE-2019-5268 | CVE-2019-5269

DrayTek: CVE-2020-14472 | CVE-2020-14473

QNAP: CVE-2020-2490 | CVE-2020-2492

CISCO: CVE-2021-1207 | CVE-2021-1209 | CVE-2021-1164 | CVE-2021-1307 | CVE-2021-1293 | CVE-2021-1295 | CVE-2021-1609 | CVE-2021-1610

D-Link: CVE-2020-25506

ZYXEL: CVE-2020-29299

XIAOMI: CVE-2020-14102

Linux Kernel: CVE-2021-4001 | CVE-2025-38477 | CVE-2025-40083 | CVE-2025-68325 | CVE-2026-22977 | CVE-2026-23276 | CVE-2026-23277 | CVE-2026-23396 | CVE-2026-23397 | CVE-2026-23398 | CVE-2026-31419 | CVE-2026-31420 | CVE-2026-31421 | CVE-2026-31422 | CVE-2026-31423 | CVE-2026-31424 | CVE-2026-31425 | CVE-2026-31426 | CVE-2026-31427 | CVE-2026-31428 | CVE-2026-43085 | CVE-2026-43086 | CVE-2026-45837 | CVE-2026-45838 | CVE-2026-45839 | CVE-2026-45840 | CVE-2026-45841 | CVE-2026-45842 | CVE-2026-45843 | CVE-2026-45844 | CVE-2026-45845 | CVE-2026-45846 | CVE-2026-46320 | CVE-2026-46321 | CVE-2026-46322 | CVE-2026-53349 | CVE-2026-52937 | CVE-2026-52938 | CVE-2026-52939 | CVE-2026-52940 | CVE-2026-52941 | CVE-2026-52942 | CVE-2026-64187 | CVE-2026-64188 | CVE-2026-64189 | CVE-2026-64190 | CVE-2026-64191 | CVE-2026-64411 | CVE-2026-64537 | CVE-2026-64538 | CVE-2026-64539 | CVE-2026-64540 | CVE-2026-64541 | CVE-2026-64542 | CVE-2026-64543 | CVE-2026-64544 | CVE-2026-64545 | CVE-2026-64546 | CVE-2026-64547 | CVE-2026-64548 | CVE-2026-64549 | CVE-2026-64550 | CVE-2026-64551 | CVE-2026-64552 | CVE-2026-64553 | CVE-2026-64554 | CVE-2026-64555

Netgear: CVE-2021-45527 | CVE-2023-36187

ASUS: CVE-2023-35086 | CVE-2023-35087 | CVE-2023-39238 | CVE-2023-39239 | CVE-2023-39240 | CVE-2024-3079 | CVE-2024-3080

QEMU: CVE-2026-66900

Other: CVE-2021-33630 | CVE-2021-33631 | CVE-2021-29629 | CVE-2020-15137 | CVE-2020-24074 | CVE-2020-15173 | CVE-2020-28194 | CVE-2020-36109 | CVE-2023-24805 | CVE-2022-43294 | CVE-2026-9539 | CVE-2026-22777

Acknowledgements


KNOW IT. HACK IT. · Research responsibly. Disclose clearly. · bestwing.me

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages