Skip to content
View minanagehsalalma's full-sized avatar
🍒
Meow ?
🍒
Meow ?

Highlights

  • Pro

Block or report minanagehsalalma

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
minanagehsalalma/README.md

Mina Nageh Salama

Burp Suite Wireshark Firmware research Hack The Box

Mina Nageh Salama profile banner

Security researcher and engineer focused on high-signal web vulnerability research, browser-side investigations, malware analysis, and practical automation that holds up under scrutiny.

GitHub followers Public repositories Public stars LinkedIn Email

Operational Snapshot

Auto-refreshed daily via GitHub Actions. Last refresh: 2026-06-20 09:37 UTC

Current role
Red Team Researcher at Synack
Independent research
Since December 2020
Current study
MSc at University of Tuscia (UNITUS), Italy

Public CVEs Assigned CVE IDs Active research

Status note: 5 public CVE records are listed below; 2 assigned CVE IDs are tracked separately until public reference URLs are available.

Contribution Activity

Isometric GitHub contribution activity for Mina Nageh Salama

What I Work On

  • Web vulnerability research with clear reproduction steps, impact framing, and remediation notes
  • Browser-extension and client-side investigations tied to real exploit paths
  • Router, Wi-Fi, and firmware security work with a bias toward findings that survive review
  • Python and JavaScript tooling that compresses testing, validation, and reporting time
  • Write-ups that stay technically dense, readable, and useful to engineers

Selected Security Work

Public CVEs

ZTE 2 models Credential Disclosure Public
CVE-2026-34474 — ZTE ZXHN H298A / H108N
Credential disclosure exposing admin and WLAN access.

ZTE 17 models Denial of Service Public
CVE-2026-34473 — ZTE ZXHN H-Series
Unauthenticated denial-of-service condition affecting a 17-model router fleet.

ZTE 1 model / 2 builds Credential Disclosure Public
CVE-2026-34472 — ZTE ZXHN H188A
Web wizard credential disclosure exposing admin, WLAN, and PPPoE secrets.

Zyxel 31 models Super-Admin Password Leak Public
CVE-2021-35036 — Zyxel CPE / ONT / LTE-5G router fleet
Super-admin password leak exposing high-privilege router credentials through Zyxel's login-privilege configuration path.

ZTE 1 model Auth Bypass Public
CVE-2021-21735 — ZTE ZXHN H168N
Authentication bypass exposing full router admin access.

Assigned CVE IDs

Assigned CVEs pending public publication in July 2026; technical details are intentionally withheld until the records are public.

Zyxel July 2026 Medium Impact Assigned
CVE-2026-8508 — Zyxel router vulnerability
Medium-impact Zyxel vulnerability assigned for July 2026 publication; technical details withheld until the public record is released.

Zyxel July 2026 High Impact Assigned
CVE-2026-6837 — Zyxel router vulnerability
High-impact Zyxel vulnerability assigned for July 2026 publication; technical details withheld until the public record is released.

Other Findings And Analyses

  • Account takeover on OLX Middle East via password-reset logic abuse
  • Race condition in Medium's voting flow that enabled count manipulation
  • ShotBird analysis in March 2026: published teardown of an ownership-transfer-to-browser-C2 chain with credential and form-data capture plus follow-on Windows credential targeting
  • Hack The Box work that sharpened systematic enumeration, common web-vulnerability discovery, and Linux privilege escalation

Selected Public Projects

Project Why it matters
Youtube-Downloader-Bookmarklet Highest-traction public repo by stars; a JavaScript bookmarklet with clear real-world usage.
huawei-dg8045-hg630-hg633-Config-file-decryption-and-password-decode Direct evidence of hands-on firmware and config-recovery work in the router/security niche.
burpsuite-custom-extension Shows active extension development for live response modification and testing workflows.
BookMarkletsWiki Demonstrates repeatable browser-side tooling instead of one-off snippets.
Ubicast-Video-Downloader Lean JavaScript utility work with a direct one-click use case.
WIFI-Location-Locator-GUI Supports the network and wireless side of the profile with a usable public tool.

Selected Gists

Gist Why it matters
ZTE ZXHN router vulnerabilities Public technical reference for the 2026 ZTE/ZXHN CVE disclosures.
Export Chrome extensions inventory Practical PowerShell tooling for browser-extension inventory, triage, and auditing.
Milanote Board to Markdown Browser automation that turns visual boards into structured markdown output.
Reddit post exporter Tampermonkey-based structured export tooling with a strong LLM and data-prep use case.

Experience And Education

  • Red Team Researcher, Synack, Inc. | Remote | June 2025 to present
  • Independent Security Researcher | Bug bounty and crowdsourced platforms | December 2020 to present
  • MSc, University of Tuscia (UNITUS), Italy | 2025 to expected July 2027
  • BSc Computer Science, Thebes Academy, Cairo | October 2021 to May 2025

Toolbox

Skills

Pinned Loading

  1. youtube-to-article-images-gifs youtube-to-article-images-gifs Public

    YouTube to article pipeline with image and GIF extraction; Supports Gemini

    Python

  2. Zyxel-4-password-decrypter Zyxel-4-password-decrypter Public

    Reverse-engineered decryption tool for Zyxel Scheme ID 4/5 passwords. Recovers plaintext administrative credentials using static AES-192-CBC parameters.

    Python

  3. RevancedForChromeExtensions RevancedForChromeExtensions Public

    ReVanced-style patch generator and patcher for unpacked Chrome extensions. It creates a portable zip bundle describing file operations (add, delete, replace) and the payload bytes needed to reprodu…

    TypeScript 2

  4. Youtube-Downloader-Bookmarklet Youtube-Downloader-Bookmarklet Public

    A Javascript Bookmarklet That creates a menu for downloading YT Vids without needing any third party app nor site.

    JavaScript 50 5

  5. BookMarkletsWiki BookMarkletsWiki Public

    A curated collection of useful and fun bookmarklets to enhance your browsing experience.

    HTML 11 1

  6. huawei-dg8045-hg630-hg633-Config-file-decryption-and-password-decode huawei-dg8045-hg630-hg633-Config-file-decryption-and-password-decode Public

    Python 15 2