About

Who I am and what I work on.

About me.

My name is Côme, I’m a 19 year old French student at Arizona State University, studying Computer Science and Philosophy.

I played with different CTF teams as a pwner:

  • ECSC Team France (Junior member in 2023 and 2024)
  • World Wide Flag
  • Shellphish (sometimes)

Been working for 2 years on mobile security as a freelancer. I’m very interested in iOS security.

CVEs

N.B: I have no time to make such work public anymore, hence why I don’t have any recent one.

  • CVE-2024-57391 -> OS command injection vulnerability affecting various GL.iNet routers running firmware version 4.x.
  • CVE-2025-2851 -> Buffer overflow vulnerability via the rpc in the plugins.so library.
  • CVE-2024-55352 -> OS command injection vulnerability affecting Cudy AC1200 Router’s web interface.

What I’ve worked on.

  • Pwn — user-land and kernel-land linux exploits (amd64, x86, aarch64, arm32, RISCV, mips, mipsel)
  • Reverse engineering — iOS and Android applications.

Elsewhere

  • GitHub: nmb3rs
  • Email: numb3rss [at] proton [dot] me