VARIoT IoT exploits database

Affected products: vendor, model and version
Type can be e.g: Remote Code Execution or Denial of Service
Look up free text in title and description

VAR-E-201907-0200 CVE-2019-1010156
CVE-2019-1010155
D-Link DSL-2750U Multiple Authentication Bypass Vulnerabilities

Related entries in the VARIoT vulnerabilities database: VAR-201907-1179, VAR-201907-1180
No EDB ID
D-Link DSL-2750U is prone to multiple authentication-bypass vulnerabilities. An attacker can exploit these issues to bypass authentication mechanism and perform unauthorized actions. This may lead to further attacks. D-Link DSL-2750U Router 1.11 is vulnerable; other versions may also be affected.
VAR-E-201907-0018 CVE-2019-1943
CISCO Small Business 200 / 300 / 500 Switches - Multiple Vulnerabilities - Hardware webapps Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201907-0394
EDB ID: 47118
CISCO Small Business 200 / 300 / 500 Switches - Multiple Vulnerabilities. CVE-2019-1943 . webapps exploit for Hardware platform
VAR-E-201907-0037 CVE-2019-13482
CVE-2019-13481
D-Link DIR-818LW Multiple Command Injection Vulnerabilities

Related entries in the VARIoT vulnerabilities database: VAR-201907-0708, VAR-201907-0707
No EDB ID
D-Link DIR-818LW is prone to multiple command-injection vulnerabilities. Exploiting these issues could allow an attacker to execute arbitrary commands in the context of the affected device. Failed exploit attempts will likely result in denial-of-service conditions. D-Link DIR-818LW devices with firmware 2.06betab01 are vulnerable.
VAR-E-201907-0133 No CVE Siemens TIA Portal - Remote Command Execution - Hardware remote Exploit EDB ID: 47083
Siemens TIA Portal - Remote Command Execution.. remote exploit for Hardware platform
VAR-E-201907-0172 No CVE Huawei HG530 Cross Site Request Forgery No EDB ID
Huawei HG530 suffers from a cross site request forgery vulnerability.
VAR-E-201907-0024 CVE-2019-0285
SAP Crystal Reports - Information Disclosure - Multiple webapps Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201904-1088
EDB ID: 47061
SAP Crystal Reports - Information Disclosure. CVE-2019-0285 . webapps exploit for Multiple platform
VAR-E-201906-0016 CVE-2019-5017
KCodes NetUSB CVE-2019-5017 Information Disclosure Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-201906-0193
No EDB ID
KCodes NetUSB is prone to an information-disclosure vulnerability. An attacker can exploit this issue to obtain sensitive information that may aid in further attacks. KCodes NetUSB.ko versions 1.0.2.66 and 1.0.2.69 are vulnerable; other versions may also be affected.
VAR-E-201906-0085 CVE-2019-5016
KCodes NetUSB CVE-2019-5016 Memory Corruption Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-201906-0192
No EDB ID
KCodes NetUSB is prone to a memory-corruption vulnerability. Attackers can exploit this issue to obtain sensitive information or crash the application resulting in a denial-of-service condition. KCodes NetUSB.ko versions 1.0.2.66 and 1.0.2.69 are vulnerable; other versions may also be affected.
VAR-E-201906-0001 CVE-2019-7228
CVE-2019-7227
CVE-2019-7231
CVE-2019-7226
CVE-2019-7232
CVE-2019-7230
ABB IDAL HTTP Server Authentication Bypass

Related entries in the VARIoT vulnerabilities database: VAR-201906-0222, VAR-201906-0218, VAR-201906-0216, VAR-201906-0221, VAR-201906-0217, VAR-201906-0220
No EDB ID
The IDAL HTTP server CGI interface contains a URL, which allows an unauthenticated attacker to bypass authentication and gain access to privileged functions. In the IDAL CGI interface, there is a URL (/cgi/loginDefaultUser), which will create a session in an authenticated state and return the session ID along with the username and plaintext password of the user. An attacker can then login with the provided credentials or supply the string 'IDALToken=......' in a cookie which will allow them to perform privileged operations such as restarting the service with /cgi/restart.
VAR-E-201906-0167 CVE-2019-12789
Telus Actiontec T2200H Local Privilege Escalation

Related entries in the VARIoT vulnerabilities database: VAR-201906-0591
No EDB ID
Telus Actiontec T2200H with firmware T2200H-31.128L.08 suffers from a local privilege escalation vulnerability.
VAR-E-201906-0133 CVE-2019-3946
CVE-2019-3947
Fuji Electric V-Server Multiple Security Vulnerabilities

Related entries in the VARIoT vulnerabilities database: VAR-201906-0327, VAR-201906-0328
No EDB ID
Fuji Electric V-Server is prone to multiple security vulnerabilities: 1. A remote denial-of-service vulnerability 2. An information disclosure vulnerability An attacker can exploit these issues to cause a denial-of-service condition or obtain sensitive information that may lead to further attacks . Versions prior to V-SFT 6.0.33.0 are vulnerable.
VAR-E-201906-0173 CVE-2019-0174
DRAM CVE-2019-0174 Local Information Disclosure Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-201906-0918
No EDB ID
DRAM is prone to an information disclosure vulnerability. A local attacker may leverage this issue to gain sensitive information from the physical address space.
VAR-E-201906-0081 CVE-2017-8404
CVE-2017-8405
CVE-2017-8406
CVE-2017-8407
CVE-2017-8408
CVE-2017-8409
CVE-2017-8410
CVE-2017-8411
CVE-2017-8412
CVE-2017-8413
CVE-2017-8414
CVE-2017-8415
CVE-2017-8416
CVE-2017-8417
Dlink DCS-1130 Command Injection / CSRF / Stack Overflow

Related entries in the VARIoT vulnerabilities database: VAR-201907-1073, VAR-201907-1077, VAR-201907-1072, VAR-201907-1070, VAR-201907-1064, VAR-201907-1075, VAR-201907-1068, VAR-201907-1069, VAR-201907-1071, VAR-201907-1066, VAR-201907-1074, VAR-201907-1065, VAR-201907-1076, VAR-201907-1067
No EDB ID
Dlink DCS-1130 suffers from command injection, cross site request forgery, stack overflow, and various other vulnerabilities.
VAR-E-201906-0039 CVE-2017-8328
CVE-2017-8329
CVE-2017-8330
CVE-2017-8331
CVE-2017-8332
CVE-2017-8333
CVE-2017-8334
CVE-2017-8335
CVE-2017-8336
CVE-2017-8337
Securifi Almond 2015 Buffer Overflow / Command Injection / XSS / CSRF

Related entries in the VARIoT vulnerabilities database: VAR-201906-0769, VAR-201906-0772, VAR-201906-0773, VAR-201906-0776, VAR-201906-0775, VAR-201906-0770, VAR-201906-0774, VAR-201906-0777, VAR-201906-0778, VAR-201906-0771
No EDB ID
Securifi Almond 2015 suffers from buffer overflow, command injection, cross site scripting, cross site request forgery, and various other vulnerabilities.
VAR-E-201906-0064 CVE-2017-13719
CVE-2017-8226
CVE-2017-8227
CVE-2017-8228
CVE-2017-8229
CVE-2017-8230
Amcrest IPM-721S Credential Disclosure / Privilege Escalation

Related entries in the VARIoT vulnerabilities database: VAR-201907-1080, VAR-201907-1081, VAR-201907-1079, VAR-201907-1078, VAR-201907-1082, VAR-201907-1046
No EDB ID
Amcrest IPM-721S suffers from credential disclosure, privilege escalation, and a long list of other vulnerabilities.
VAR-E-201906-0083 CVE-2018-19864
NUUO NVRMini 2 3.9.1 - 'sscanf' Stack Overflow - Hardware remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201812-1058
EDB ID: 46960
NUUO NVRMini 2 3.9.1 - 'sscanf' Stack Overflow. CVE-2018-19864 . remote exploit for Hardware platform
VAR-E-201905-0230 CVE-2019-12195
TP-LINK TL-WR840N v5 00000005 - Cross-Site Scripting - Hardware webapps Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201905-1254
EDB ID: 46882
TP-LINK TL-WR840N v5 00000005 - Cross-Site Scripting. CVE-2019-12195 . webapps exploit for Hardware platform
VAR-E-201905-0120 CVE-2014-9418
Huawei eSpace 1.1.11.103 - 'ContactsCtrl.dll' / 'eSpaceStatusCtrl.dll' ActiveX Heap Overflow - Windows dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201412-0110
EDB ID: 46868
Huawei eSpace 1.1.11.103 - 'ContactsCtrl.dll' / 'eSpaceStatusCtrl.dll' ActiveX Heap Overflow. CVE-2014-9418 . dos exploit for Windows platform
VAR-E-201905-0207 CVE-2014-9417
Huawei eSpace 1.1.11.103 - Image File Format Handling Buffer Overflow - Windows dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201412-0109
EDB ID: 46867
Huawei eSpace 1.1.11.103 - Image File Format Handling Buffer Overflow. CVE-2014-9417 . dos exploit for Windows platform
VAR-E-201905-0010 CVE-2014-9416
Huawei eSpace 1.1.11.103 - DLL Hijacking - Windows local Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201412-0108
EDB ID: 46866
Huawei eSpace 1.1.11.103 - DLL Hijacking. CVE-2014-9416 . local exploit for Windows platform