VARIoT IoT exploits database

VAR-E-201503-0127 |
CVE-2015-2797 |
Airties Air5650TT - Remote Stack Overflow - Multiple remote Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201506-0118 | EDB ID: 36577 |
Airties Air5650TT - Remote Stack Overflow. CVE-120335CVE-2015-2797 . remote exploit for Multiple platform
VAR-E-201503-0505 |
CVE-2015-2681 |
ASUS RT-G32 Router 'start_apply.htm' Multiple Cross Site Scripting Vulnerabilities
Related entries in the VARIoT vulnerabilities database: VAR-201503-0303 | No EDB ID |
ASUS RT-G32 Router is prone to multiple cross-site scripting vulnerabilities.
An attacker may exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, perform unauthorized actions, and disclose or modify sensitive information.
ASUS RT-G32 router running firmware versions 2.0.2.6, and 2.0.3.2 are vulnerable.
VAR-E-201503-0117 | No CVE | Citrix NetScaler VPX Cross Site Scripting | No EDB ID |
It was discovered that the help pages of Citrix VPX are vulnerable to cross site scripting.
VAR-E-201503-0456 |
CVE-2014-9207 |
Cimon CmnView CVE-2014-9207 DLL Loading Arbitrary Code Execution Vulnerability
Related entries in the VARIoT vulnerabilities database: VAR-201503-0334 | No EDB ID |
Cimon CmnView is prone to a vulnerability that lets attackers execute arbitrary code.
Successful exploits will allow the attackers to execute arbitrary code in the context of the user running the affected application.
VAR-E-201503-0247 | No CVE | Sagem F@st 3304-V2 - Telnet Crash (PoC) - Hardware dos Exploit | EDB ID: 36309 |
Sagem F@st 3304-V2 - Telnet Crash (PoC). CVE-119602 . dos exploit for Hardware platform
VAR-E-201503-0445 | No CVE | ASUS RT-G32 Cross Site Request Forgery / Cross Site Scripting | No EDB ID |
ASUS RT-G32 suffers from cross site request forgery and cross site scripting vulnerabilities.
VAR-E-201503-0451 | No CVE | Sagem F@st 3304-V2 - Local File Inclusion - Hardware webapps Exploit | EDB ID: 36241 |
Sagem F@st 3304-V2 - Local File Inclusion. CVE-119605 . webapps exploit for Hardware platform
VAR-E-201502-0232 |
CVE-2015-2080 | Nanometrics Centaur 4.3.23 - Unauthenticated Remote Memory Leak - Hardware webapps Exploit | EDB ID: 48098 |
Nanometrics Centaur 4.3.23 - Unauthenticated Remote Memory Leak.. webapps exploit for Hardware platform
VAR-E-201502-0233 |
CVE-2015-2080 | Inductive Automation Ignition 7.8.1 - Remote Leakage Of Shared Buffers - Multiple remote Exploit | EDB ID: 39455 |
Inductive Automation Ignition 7.8.1 - Remote Leakage Of Shared Buffers. CVE-2015-2080 . remote exploit for Multiple platform
VAR-E-201502-0354 | No CVE | Multiple D-Link and TRENDnet Routers 'ncc/ncc2' Service Multiple Security Vulnerabilities | No EDB ID |
Multiple D-Link and TRENDnet routers are prone to a local unauthenticated vulnerability, a remote unauthenticated vulnerability and a cross-site request-forgery vulnerability.
An attacker can exploit this issue to perform certain unauthorized actions and gain unauthorized root access to an affected device. Successful exploits will result in the complete compromise of an affected device.
Following products are vulnerable:
D-Link DIR-820L (Rev A) 1.02B10, DIR-820L (Rev A) 1.05B03, and DIR-820L (Rev B) 2.01b02
TRENDnet TEW-731BR (Rev 2) 2.01b01
VAR-E-201502-0108 | No CVE | D-Link DSL-2640B ADSL Router - 'ddnsmngr' Remote DNS Change - Hardware webapps Exploit | EDB ID: 36105 |
D-Link DSL-2640B ADSL Router - 'ddnsmngr' Remote DNS Change. CVE-117675 . webapps exploit for Hardware platform
VAR-E-201502-0097 | No CVE | D-Link DSL-2640B Unauthenticated Remote DNS Changer | No EDB ID |
Remote exploit for changing DNS settings unauthenticated on the D-Link DSL-2640B.
VAR-E-201502-0069 | No CVE | Multiple NetGear Routers SOAP Service Authentication Bypass Vulnerability | No EDB ID |
Multiple NetGear Routers are prone to a remote authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and gain potentially sensitive information.
NetGear WNDR3700v4 V1.0.0.4SH, WNDR3700v4 V1.0.1.52, WNR2200 V1.0.1.88, WNR2500 V1.0.0.24 are vulnerable.
VAR-E-201501-0464 | No CVE | D-Link DSL-2740R Unauthenticated Remote DNS Change | No EDB ID |
Exploit for remotely changing DNS settings on the D-Link DSL-2740R router.
VAR-E-201501-0340 | No CVE | D-Link DSL-2740R - Remote DNS Change - Hardware remote Exploit | EDB ID: 35917 |
D-Link DSL-2740R - Remote DNS Change. CVE-117675 . remote exploit for Hardware platform
VAR-E-201501-0033 |
CVE-2014-0997 |
Android WiFi-Direct - Denial of Service - Android dos Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201709-0150 | EDB ID: 35913 |
Android WiFi-Direct - Denial of Service. CVE-2014-0997CVE-117581 . dos exploit for Android platform
VAR-E-201501-0004 |
CVE-2014-9198 |
Schneider Electric ETG3000 FactoryCast HMI Gateway Authentication Bypass Vulnerability
Related entries in the VARIoT vulnerabilities database: VAR-201501-0403 | No EDB ID |
Schneider Electric ETG3000 FactoryCast HMI Gateway is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and gain unauthorized access to the affected device. This may aid in further attacks.
VAR-E-201501-0484 |
CVE-2015-2054 |
Sierra Wireless AirCard 'export.cfg' HTTP Header Injection Vulnerability
Related entries in the VARIoT vulnerabilities database: VAR-201502-0204 | No EDB ID |
Sierra Wireless AirCard is prone to an HTTP header-injection vulnerability.
A successful attack may allow attackers to insert a crafted HTTP header into an HTTP response that could cause a web page redirection to a possible malicious website; this may aid in launching further attacks.
Sierra Wireless AirCard versions 760S, 762S, and 763S are vulnerable.
VAR-E-201501-0445 |
CVE-2014-9510 |
TP-Link TL-WR840N 'Import Configuration' Option Cross Site Request Forgery Vulnerability
Related entries in the VARIoT vulnerabilities database: VAR-201501-0652 | No EDB ID |
TP-Link TL-WR840N is prone to a cross-site request-forgery vulnerability because it fails to properly validate HTTP requests.
An attacker can exploit this issue to perform certain unauthorized administrative actions. Other attacks are also possible.
TP-Link TL-WR840N Router running firmware 3.13.27 Build 140714 and prior are vulnerable.
VAR-E-201412-0184 | No CVE | Advantech AdamView 4.30.003 - (.gni) SEH Buffer Overflow Exploit | No EDB ID |