you can use -e=extra_param in case the exploit changes the password or targets a local machine
if you are scanning a router you can pass a local ip in the -e param to target a local machine usually exploits like this will give you a computer obj with guest or root permissions
all null results will be hidden unless you use the --show-null option in the params