>_ pwn.re

Offensive security research

I find and report vulnerabilities before attackers do.

Independent security researcher working across firmware and IoT, mobile, and web applications. Static-first reverse engineering, custom tooling, and coordinated disclosure.

whoami → Andrii Timofeev · Kyiv · reverse engineer

latest → CVE-2026-77538 · Ubiquiti UniFi Connect · CVSS 8.2

What I work on

Research focus

01 Firmware & IoT

Reverse engineering embedded devices and network gear: extracting firmware, mapping attack surface, and finding memory-safety and access-control bugs in native services.

IDA Pro Ghidra binwalk ARM/ARM64

02 Mobile & Android

Application and platform security on Android: static and dynamic analysis of apps and native libraries, auth and logic flaws, and path-traversal classes at scale.

jadx Frida apktool Burp

03 Web & application

Access control, injection, and business-logic vulnerabilities in web backends and APIs, reported through bug bounty and coordinated disclosure channels.

HTTP nginx internals PoC dev

Featured advisory

Latest public disclosure

HIGH · CVSS 8.2
CVE-2026-77538
Improper access control in Ubiquiti UniFi Connect Application allows an unauthenticated, network-adjacent attacker to escalate privileges within the app.
Vendor Ubiquiti Weakness CWE-284 Fixed 3.24.22 Disclosed 2026-08-26

Read the full writeup

Selected results

Track record

  • CVE CVE-2026-77538 — improper access control in Ubiquiti UniFi Connect (CVSS 8.2). Reported via bug bounty; fixed and publicly disclosed by the vendor.
  • Bug bounty Reported and rewarded findings through HackerOne and Bugcrowd, including Ubiquiti's program.
  • Vendor Acknowledged report to Samsung Mobile Security.
  • Open source 19 CVE IDs assigned by MITRE for Zip Slip path-traversal issues in open-source Android and Java projects.

About

Approach

I am an independent security researcher based in Kyiv. My work starts with static reverse engineering: pulling apart firmware images, native binaries, and mobile apps to understand how they actually behave, then confirming findings dynamically on real hardware where it matters.

I build my own tooling and automation around industry-standard reversing platforms to cover more surface faster. Everything I report goes through responsible, coordinated disclosure. Vendors and programs get the details and time to fix before anything becomes public.

Contact

Get in touch

Open to vulnerability research, reverse-engineering, and red-team contract work, and to coordinating disclosure on issues in scope.

Security contact & disclosure policy: /.well-known/security.txt