A long process start to finish reverse engineering a router, pulling its firmware via UART and netcat, binwalk, IDA pro bug hunting, vuln identifying and finally locating a remote RCE stack smasher and verifying via a qemu MIPS emulator. I started this in August on a whim.
Finally, an 0day, been forever. This time in a Broadcom utility program thingy in a router. Stack smasher via strcpy, byte length 131 bytes, with user controlled input as char *string argument. I thought they were all gone, but then who the hell is opening up router firmware?