VARIoT news about IoT security

Trust: 3.75

Fetched: Nov. 21, 2025, 9:33 a.m., Published: Nov. 17, 2025, midnight
Vulnerabilities: path traversal
Affected productsExternal IDs

Trust: 3.5

Fetched: Nov. 21, 2025, 9:33 a.m., Published: Nov. 12, 2025, 8:46 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: palo model: networks
vendor: cisco model: firepower
db: NVD ids: CVE-2025-20362, CVE-2025-20333

Trust: 4.0

Fetched: Nov. 21, 2025, 9:32 a.m., Published: Nov. 20, 2025, 1:03 p.m.
Vulnerabilities: authentication bypass
Affected productsExternal IDs
db: NVD ids: CVE-2025-64513

Trust: 3.0

Fetched: Nov. 21, 2025, 9:32 a.m., Published: Nov. 20, 2025, 11:04 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: google model: android
vendor: google model: google chrome
vendor: google model: chrome
Related entries in the VARIoT vulnerabilities database: VAR-202511-1189, VAR-202511-1037, VAR-202511-0385, VAR-202511-1325

Trust: 5.5

Fetched: Nov. 21, 2025, 9:31 a.m., Published: Nov. 19, 2025, 12:04 p.m.
Vulnerabilities: command execution, buffer overflow, command injection...
Affected productsExternal IDs
vendor: d-link model: router
vendor: d-link model: dir-878
db: NVD ids: CVE-2025-60674, CVE-2025-60676, CVE-2025-60672, CVE-2025-60673

Trust: 3.25

Fetched: Nov. 21, 2025, 9:31 a.m., Published: Nov. 19, 2025, 1:44 p.m.
Vulnerabilities: -
Affected productsExternal IDs
Related entries in the VARIoT vulnerabilities database: VAR-202511-1189, VAR-202511-1037, VAR-202511-0385, VAR-202511-1325

Trust: 5.5

Fetched: Nov. 21, 2025, 9:29 a.m., Published: Nov. 19, 2025, 9:36 a.m.
Vulnerabilities: memory corruption, buffer overflow, code execution
Affected productsExternal IDs
vendor: d-link model: router
vendor: d-link model: dir-878
db: NVD ids: CVE-2025-60674, CVE-2025-60676, CVE-2025-60672, CVE-2025-60673

Trust: 3.75

Fetched: Nov. 21, 2025, 9:28 a.m., Published: Nov. 19, 2025, midnight
Vulnerabilities: authentication bypass, path traversal
Affected productsExternal IDs
db: NVD ids: CVE-2025-64446

Trust: 5.25

Fetched: Nov. 21, 2025, 9:27 a.m., Published: Nov. 19, 2025, 12:30 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: vivotek model: pt7135
db: NVD ids: CVE-2025-12592

Trust: 3.75

Fetched: Nov. 21, 2025, 9:27 a.m., Published: Nov. 12, 2025, 8:46 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: cisco model: webex
vendor: cisco model: cisco webex
vendor: cisco model: firepower
vendor: cisco systems model: webex
vendor: cisco systems model: cisco webex
vendor: cisco systems model: firepower
db: NVD ids: CVE-2025-20362, CVE-2025-20333

Trust: 3.75

Fetched: Nov. 21, 2025, 9:26 a.m., Published: Nov. 20, 2025, 10:35 a.m.
Vulnerabilities: default credentials, code execution
Affected productsExternal IDs
vendor: d-link model: router
vendor: d-link model: dir-878
Related entries in the VARIoT vulnerabilities database: VAR-202404-0070, VAR-202404-0069

Trust: 4.75

Fetched: Nov. 21, 2025, 9:26 a.m., Published: Nov. 20, 2025, 5:45 p.m.
Vulnerabilities: command injection
Affected productsExternal IDs
vendor: palo model: networks
vendor: d-link model: dns-325
vendor: d-link model: dns-320l
vendor: d-link model: dns-327l
vendor: d-link model: dns-340l
vendor: palo alto networks model: networks
vendor: trend model: security
db: NVD ids: CVE-2024-3273, CVE-2024-3272

Trust: 3.0

Fetched: Nov. 21, 2025, 9:25 a.m., Published: Nov. 20, 2025, 4:59 p.m.
Vulnerabilities: privilege escalation
Affected productsExternal IDs

Trust: 4.75

Fetched: Nov. 21, 2025, 9:25 a.m., Published: Nov. 27, 2025, midnight
Vulnerabilities: authentication bypass, path traversal, improper access control
Affected productsExternal IDs
db: NVD ids: CVE-2025-64446

Trust: 3.5

Fetched: Nov. 21, 2025, 9:24 a.m., Published: Nov. 12, 2025, 8:46 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: tp-link model: routers
vendor: cisco model: routers
vendor: cisco model: firepower
db: NVD ids: CVE-2025-20362, CVE-2025-33073, CVE-2025-20333, CVE-2025-7851, CVE-2025-7850

Trust: 3.75

Fetched: Nov. 21, 2025, 9:24 a.m., Published: Nov. 19, 2025, 1:39 p.m.
Vulnerabilities: path traversal, os command injection, command injection
Affected productsExternal IDs
db: NVD ids: CVE-2025-58034, CVE-2025-64446
Related entries in the VARIoT vulnerabilities database: VAR-202504-1580, VAR-202309-0729

Trust: 5.5

Fetched: Nov. 21, 2025, 9:21 a.m., Published: Nov. 20, 2025, 12:21 p.m.
Vulnerabilities: command execution, os command injection, arbitrary command execution...
Affected productsExternal IDs
vendor: asus model: router
vendor: asus model: routers
vendor: asus model: asus
vendor: google model: nexus
vendor: google model: home
vendor: trend model: security
db: NVD ids: CVE-2024-12912, CVE-2023-41346, CVE-2025-2492, CVE-2023-41348, CVE-2023-39780, CVE-2023-41345, CVE-2023-41347

Trust: 4.0

Fetched: Nov. 21, 2025, 9:20 a.m., Published: Nov. 14, 2025, 7:16 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: asus model: asus
vendor: asus model: dsl-ac51
vendor: asus model: dsl-ac750
vendor: asus model: router
vendor: asus model: dsl-n16
vendor: asus model: routers
db: NVD ids: CVE-2025-59367
Related entries in the VARIoT vulnerabilities database: VAR-202504-1580, VAR-202309-0729

Trust: 5.5

Fetched: Nov. 21, 2025, 9:19 a.m., Published: Nov. 20, 2025, 7:28 p.m.
Vulnerabilities: command injection, code execution
Affected productsExternal IDs
vendor: asus model: router
vendor: asus model: rt-ac1300uhp
vendor: asus model: rt-ac1300gplus
vendor: asus model: gt-ac5300
vendor: asus model: gt-ax11000
vendor: asus model: 4g-ac55u
vendor: asus model: routers
vendor: asus model: dsl-ac68u
vendor: asus model: asus
vendor: asus model: rt-ac1200hp
db: NVD ids: CVE-2025-2492, CVE-2023-39780, CVE-2024-12912

Trust: 4.75

Fetched: Nov. 21, 2025, 9:18 a.m., Published: -
Vulnerabilities: privilege escalation, denial of service
Affected productsExternal IDs
db: NVD ids: CVE-2025-61661