VARIoT IoT exploits database

Affected products: vendor, model and version
Type can be e.g: Remote Code Execution or Denial of Service
Look up free text in title and description

VAR-E-201503-0127 CVE-2015-2797
Airties Air5650TT - Remote Stack Overflow - Multiple remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201506-0118
EDB ID: 36577
Airties Air5650TT - Remote Stack Overflow. CVE-120335CVE-2015-2797 . remote exploit for Multiple platform
VAR-E-201503-0505 CVE-2015-2681
ASUS RT-G32 Router 'start_apply.htm' Multiple Cross Site Scripting Vulnerabilities

Related entries in the VARIoT vulnerabilities database: VAR-201503-0303
No EDB ID
ASUS RT-G32 Router is prone to multiple cross-site scripting vulnerabilities. An attacker may exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, perform unauthorized actions, and disclose or modify sensitive information. ASUS RT-G32 router running firmware versions 2.0.2.6, and 2.0.3.2 are vulnerable.
VAR-E-201503-0117 No CVE Citrix NetScaler VPX Cross Site Scripting No EDB ID
It was discovered that the help pages of Citrix VPX are vulnerable to cross site scripting.
VAR-E-201503-0456 CVE-2014-9207
Cimon CmnView CVE-2014-9207 DLL Loading Arbitrary Code Execution Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-201503-0334
No EDB ID
Cimon CmnView is prone to a vulnerability that lets attackers execute arbitrary code. Successful exploits will allow the attackers to execute arbitrary code in the context of the user running the affected application.
VAR-E-201503-0247 No CVE Sagem F@st 3304-V2 - Telnet Crash (PoC) - Hardware dos Exploit EDB ID: 36309
Sagem F@st 3304-V2 - Telnet Crash (PoC). CVE-119602 . dos exploit for Hardware platform
VAR-E-201503-0445 No CVE ASUS RT-G32 Cross Site Request Forgery / Cross Site Scripting No EDB ID
ASUS RT-G32 suffers from cross site request forgery and cross site scripting vulnerabilities.
VAR-E-201503-0451 No CVE Sagem F@st 3304-V2 - Local File Inclusion - Hardware webapps Exploit EDB ID: 36241
Sagem F@st 3304-V2 - Local File Inclusion. CVE-119605 . webapps exploit for Hardware platform
VAR-E-201502-0232 CVE-2015-2080
Nanometrics Centaur 4.3.23 - Unauthenticated Remote Memory Leak - Hardware webapps Exploit EDB ID: 48098
Nanometrics Centaur 4.3.23 - Unauthenticated Remote Memory Leak.. webapps exploit for Hardware platform
VAR-E-201502-0233 CVE-2015-2080
Inductive Automation Ignition 7.8.1 - Remote Leakage Of Shared Buffers - Multiple remote Exploit EDB ID: 39455
Inductive Automation Ignition 7.8.1 - Remote Leakage Of Shared Buffers. CVE-2015-2080 . remote exploit for Multiple platform
VAR-E-201502-0354 No CVE Multiple D-Link and TRENDnet Routers 'ncc/ncc2' Service Multiple Security Vulnerabilities No EDB ID
Multiple D-Link and TRENDnet routers are prone to a local unauthenticated vulnerability, a remote unauthenticated vulnerability and a cross-site request-forgery vulnerability. An attacker can exploit this issue to perform certain unauthorized actions and gain unauthorized root access to an affected device. Successful exploits will result in the complete compromise of an affected device. Following products are vulnerable: D-Link DIR-820L (Rev A) 1.02B10, DIR-820L (Rev A) 1.05B03, and DIR-820L (Rev B) 2.01b02 TRENDnet TEW-731BR (Rev 2) 2.01b01
VAR-E-201502-0108 No CVE D-Link DSL-2640B ADSL Router - 'ddnsmngr' Remote DNS Change - Hardware webapps Exploit EDB ID: 36105
D-Link DSL-2640B ADSL Router - 'ddnsmngr' Remote DNS Change. CVE-117675 . webapps exploit for Hardware platform
VAR-E-201502-0097 No CVE D-Link DSL-2640B Unauthenticated Remote DNS Changer No EDB ID
Remote exploit for changing DNS settings unauthenticated on the D-Link DSL-2640B.
VAR-E-201502-0069 No CVE Multiple NetGear Routers SOAP Service Authentication Bypass Vulnerability No EDB ID
Multiple NetGear Routers are prone to a remote authentication-bypass vulnerability. An attacker can exploit this issue to bypass the authentication mechanism and gain potentially sensitive information. NetGear WNDR3700v4 V1.0.0.4SH, WNDR3700v4 V1.0.1.52, WNR2200 V1.0.1.88, WNR2500 V1.0.0.24 are vulnerable.
VAR-E-201501-0464 No CVE D-Link DSL-2740R Unauthenticated Remote DNS Change No EDB ID
Exploit for remotely changing DNS settings on the D-Link DSL-2740R router.
VAR-E-201501-0340 No CVE D-Link DSL-2740R - Remote DNS Change - Hardware remote Exploit EDB ID: 35917
D-Link DSL-2740R - Remote DNS Change. CVE-117675 . remote exploit for Hardware platform
VAR-E-201501-0033 CVE-2014-0997
Android WiFi-Direct - Denial of Service - Android dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201709-0150
EDB ID: 35913
Android WiFi-Direct - Denial of Service. CVE-2014-0997CVE-117581 . dos exploit for Android platform
VAR-E-201501-0004 CVE-2014-9198
Schneider Electric ETG3000 FactoryCast HMI Gateway Authentication Bypass Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-201501-0403
No EDB ID
Schneider Electric ETG3000 FactoryCast HMI Gateway is prone to an authentication-bypass vulnerability. An attacker can exploit this issue to bypass the authentication mechanism and gain unauthorized access to the affected device. This may aid in further attacks.
VAR-E-201501-0484 CVE-2015-2054
Sierra Wireless AirCard 'export.cfg' HTTP Header Injection Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-201502-0204
No EDB ID
Sierra Wireless AirCard is prone to an HTTP header-injection vulnerability. A successful attack may allow attackers to insert a crafted HTTP header into an HTTP response that could cause a web page redirection to a possible malicious website; this may aid in launching further attacks. Sierra Wireless AirCard versions 760S, 762S, and 763S are vulnerable.
VAR-E-201501-0445 CVE-2014-9510
TP-Link TL-WR840N 'Import Configuration' Option Cross Site Request Forgery Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-201501-0652
No EDB ID
TP-Link TL-WR840N is prone to a cross-site request-forgery vulnerability because it fails to properly validate HTTP requests. An attacker can exploit this issue to perform certain unauthorized administrative actions. Other attacks are also possible. TP-Link TL-WR840N Router running firmware 3.13.27 Build 140714 and prior are vulnerable.
VAR-E-201412-0184 No CVE Advantech AdamView 4.30.003 - (.gni) SEH Buffer Overflow Exploit No EDB ID