Skip to content
View winmin's full-sized avatar
🤣
Read the fucking source code
🤣
Read the fucking source code

Organizations

@FlappyPig @r3kapig

Block or report winmin

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
winmin/README.md
Language: English · 简体中文

About

I research vulnerabilities in the Linux kernel, embedded systems, and network appliances. My work spans source auditing, fuzzing, exploit development, and responsible disclosure.

CTF player with FlappyPig and r3kapig.

85 public CVEs across 11 ecosystems, including 47 Linux kernel findings.

Selected research

Focus

  • Surfaces — Linux kernel, embedded devices, IoT, and network appliances
  • Methods — source auditing, fuzzing, reverse engineering, and exploit development
  • Practice — PWN, CTF, root-cause analysis, and responsible disclosure

Recognition

  • 2025 · 1st place — 0x300 · Tianwang Cup ITAI Critical Product Vulnerability Discovery Challenge
  • 2024 · Two 1st-place finishes — 0x300 · Tianwang Cup ITAI Critical Product Vulnerability Discovery Challenge · Matrix Cup Hardware & Software Security Testing Competition
  • 2023 · Champion — 跃哥我真不会啊 · Datacon Vulnerability Analysis Track
    2nd place — 0x300 · CSST Tianwang Cup
Earlier recognition · 2018–2021
  • 2021 · 2nd place — 0x300 · Inaugural ITAI Critical Product Security Challenge
    Best Vulnerability Reproduction — Tianfu Cup · Docker Escape & Ubuntu LPE
  • 2019 — Chaitin · GeekPwn & HUAWEI Smart Device Security Challenge · MAXHUB Exploit
  • 2018 · Best Demo Award — Piggy mine · GeekPwn

Publications

  • CTF Training Camp: Technical Deep Dives, Problem-Solving Methods, and Competition SkillsAuthor
  • Fuzzing Against the Machine
    Automate vulnerability research with emulated IoT devices on QEMUTranslator

Disclosure archive

The archive below is synchronized from bestwing.me every week.

Browse the complete CVE index · grouped by vendor

HUAWEI: CVE-2019-5268 | CVE-2019-5269

DrayTek: CVE-2020-14472 | CVE-2020-14473

QNAP: CVE-2020-2490 | CVE-2020-2492

CISCO: CVE-2021-1207 | CVE-2021-1209 | CVE-2021-1164 | CVE-2021-1307 | CVE-2021-1293 | CVE-2021-1295 | CVE-2021-1609 | CVE-2021-1610

D-Link: CVE-2020-25506

ZYXEL: CVE-2020-29299

XIAOMI: CVE-2020-14102

Linux Kernel: CVE-2021-4001 | CVE-2025-38477 | CVE-2025-40083 | CVE-2025-68325 | CVE-2026-22977 | CVE-2026-23276 | CVE-2026-23277 | CVE-2026-23396 | CVE-2026-23397 | CVE-2026-23398 | CVE-2026-31419 | CVE-2026-31420 | CVE-2026-31421 | CVE-2026-31422 | CVE-2026-31423 | CVE-2026-31424 | CVE-2026-31425 | CVE-2026-31426 | CVE-2026-31427 | CVE-2026-31428 | CVE-2026-43085 | CVE-2026-43086 | CVE-2026-45837 | CVE-2026-45838 | CVE-2026-45839 | CVE-2026-45840 | CVE-2026-45841 | CVE-2026-45842 | CVE-2026-45843 | CVE-2026-45844 | CVE-2026-45845 | CVE-2026-45846 | CVE-2026-46320 | CVE-2026-46321 | CVE-2026-46322 | CVE-2026-53349 | CVE-2026-52937 | CVE-2026-52938 | CVE-2026-52939 | CVE-2026-52940 | CVE-2026-52941 | CVE-2026-52942 | CVE-2026-64187 | CVE-2026-64188 | CVE-2026-64189 | CVE-2026-64190 | CVE-2026-64191

Netgear: CVE-2021-45527 | CVE-2023-36187

ASUS: CVE-2023-35086 | CVE-2023-35087 | CVE-2023-39238 | CVE-2023-39239 | CVE-2023-39240 | CVE-2024-3079 | CVE-2024-3080

Other: CVE-2021-33630 | CVE-2021-33631 | CVE-2021-29629 | CVE-2020-15137 | CVE-2020-24074 | CVE-2020-15173 | CVE-2020-28194 | CVE-2020-36109 | CVE-2023-24805 | CVE-2022-43294 | CVE-2026-9539 | CVE-2026-22777

Acknowledgements


KNOW IT. HACK IT. · Research responsibly. Disclose clearly. · bestwing.me

Pinned Loading

  1. PwnBox PwnBox Public

    Script to setup pwn environment with Docker

    Python 50 9

  2. evil-opencode evil-opencode Public

    Forked from anomalyco/opencode

    The open source coding agent. (Unleashed 、Removing LLM safety guardrails)

    TypeScript 233 22

  3. ida-headless-mcp ida-headless-mcp Public

    Forked from mrexodia/ida-pro-mcp

    AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.

    Python 71 8

  4. kernel-vuln-analyzer kernel-vuln-analyzer Public

    Claude Code skill for Linux kernel vulnerability analysis — from crash log triage to patch verification

    Shell 39

  5. vulhub/vulhub vulhub/vulhub Public

    Pre-Built Vulnerable Environments Based on Docker-Compose

    Dockerfile 21.1k 4.8k

  6. ctf-wiki/ctf-wiki ctf-wiki/ctf-wiki Public

    Come and join us, we need you!

    Python 9.5k 1.4k