VARIoT IoT exploits database

Affected products: vendor, model and version
Type can be e.g: Remote Code Execution or Denial of Service
Look up free text in title and description

VAR-E-201912-0092 No CVE Omron PLC 1.0.0 Denial Of Service No EDB ID
Omron PLC version 1.0.0 suffers from a denial of service vulnerability.
VAR-E-201911-0191 CVE-2019-18922
Allied Telesis AT-GS950/8 Directory Traversal

Related entries in the VARIoT vulnerabilities database: VAR-201911-0645
No EDB ID
Allied Telesis AT-GS950/8 up until firmware AT-S107 version 1.1.3 [1.00.047] suffers from a directory traversal vulnerability.
VAR-E-201911-0047 No CVE InduSoft Web Studio 8.1 SP1 Denial Of Service No EDB ID
InduSoft Web Studio version 8.1 SP1 suffers from a denial of service vulnerability.
VAR-E-201911-0154 No CVE InduSoft Web Studio 8.1 SP1 - "Atributos" Denial of Service (PoC) - Windows dos Exploit EDB ID: 47717
InduSoft Web Studio 8.1 SP1 - "Atributos" Denial of Service (PoC).. dos exploit for Windows platform
VAR-E-201911-0217 CVE-2019-16758
Lexmark Services Monitor 2.27.4.0.39 - Directory Traversal - Hardware webapps Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201911-1137
EDB ID: 47663
Lexmark Services Monitor 2.27.4.0.39 - Directory Traversal. CVE-2019-16758 . webapps exploit for Hardware platform
VAR-E-201911-0219 No CVE Fastweb Fastgate 0.00.81 Remote Code Execution No EDB ID
Fastweb Fastgate version 0.00.81 suffers from a remote code execution vulnerability.
VAR-E-201911-0188 No CVE Fastweb Fastgate 0.00.81 - Remote Code Execution - Hardware webapps Exploit EDB ID: 47654
Fastweb Fastgate 0.00.81 - Remote Code Execution.. webapps exploit for Hardware platform
VAR-E-201911-0149 CVE-2019-18793
Parallels Plesk Panel 9.5 Cross Site Scripting

Related entries in the VARIoT vulnerabilities database: VAR-201911-0702
No EDB ID
Parallels Plesk Panel version 9.5 suffers from a cross site scripting vulnerability.
VAR-E-201910-0007 No CVE Intelbras Router WRN150 1.0.18 Cross Site Request Forgery No EDB ID
Intelbras Router WRN150 version 1.0.18 suffers from a cross site request forgery vulnerability.
VAR-E-201910-0138 No CVE Intelbras Router WRN150 1.0.18 - Cross-Site Request Forgery - Hardware webapps Exploit EDB ID: 47545
Intelbras Router WRN150 1.0.18 - Cross-Site Request Forgery.. webapps exploit for Hardware platform
VAR-E-201910-0139 CVE-2019-10963
CVE-2019-10969
Moxa EDR-810 - Command Injection / Information Disclosure - Hardware remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201910-1593, VAR-201910-1701
EDB ID: 47536
Moxa EDR-810 - Command Injection / Information Disclosure. CVE-2019-10969CVE-2019-10963 . remote exploit for Hardware platform
VAR-E-201910-0056 CVE-2019-12147
Sangoma SBC 2.3.23-119-GA Unauthenticated User Creation

Related entries in the VARIoT vulnerabilities database: VAR-201910-1676
No EDB ID
A remotely exploitable vulnerability exists in the 2.3.23-119-GA version of Sangoma SBC that would allow an unauthenticated user to create a privileged user on the system using the web application login interface.
VAR-E-201910-0169 No CVE Intelbras Router WRN150 1.0.18 Cross Site Scripting No EDB ID
Intelbras Router WRN150 version 1.0.18 suffers from a persistent cross site scripting vulnerability.
VAR-E-201910-0177 No CVE Intelbras Router WRN150 1.0.18 - Persistent Cross-Site Scripting - Hardware webapps Exploit EDB ID: 47491
Intelbras Router WRN150 1.0.18 - Persistent Cross-Site Scripting.. webapps exploit for Hardware platform
VAR-E-201910-0170 CVE-2019-6971
TP-Link TL-WR1043ND 2 - Authentication Bypass - Hardware webapps Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201906-0410
EDB ID: 47483
TP-Link TL-WR1043ND 2 - Authentication Bypass. CVE-2019-6971 . webapps exploit for Hardware platform
VAR-E-201909-0001 CVE-2019-1914
CVE-2019-1913
CVE-2019-1912
Cisco Small Business 220 Series - Multiple Vulnerabilities - Hardware remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201908-1018, VAR-201908-1017, VAR-201908-1016
EDB ID: 47442
Cisco Small Business 220 Series - Multiple Vulnerabilities. CVE-2019-1914CVE-2019-1913CVE-2019-1912 . remote exploit for Hardware platform
VAR-E-201909-0219 No CVE IntelBras TELEFONE IP TIP200/200 LITE 60.61.75.15 Arbitrary File Read No EDB ID
IntelBras TELEFONE IP TIP200/200 LITE version 60.61.75.15 dumpConfigFile pre-authentication remote arbitrary file read exploit.
VAR-E-201909-0134 No CVE IntelBras TELEFONE IP TIP200/200 LITE 60.61.75.15 - Arbitrary File Read - Hardware remote Exploit EDB ID: 47337
IntelBras TELEFONE IP TIP200/200 LITE 60.61.75.15 - Arbitrary File Read.. remote exploit for Hardware platform
VAR-E-201908-0016 CVE-2019-13101
D-Link DIR-600M - Authentication Bypass (Metasploit) - Hardware webapps Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201908-0438
EDB ID: 47250
D-Link DIR-600M - Authentication Bypass (Metasploit). CVE-2019-13101 . webapps exploit for Hardware platform
VAR-E-201908-0137 No CVE Cisco Catalyst 3850 Series Device Manager 3.6.10E Cross Site Request Forgery No EDB ID
Cisco Catalyst 3850 Series Device Manager version 3.6.10E suffers from a cross site request forgery vulnerability.