VARIoT news about IoT security

Related entries in the VARIoT vulnerabilities database: VAR-202502-0055

Trust: 4.25

Fetched: Feb. 7, 2025, 9:09 a.m., Published: Feb. 7, 2025, midnight
Vulnerabilities: information disclosure, denial of service, code execution
Affected productsExternal IDs
vendor: motorola model: motorola
vendor: motorola model: android
vendor: google model: android
vendor: google model: pixel
vendor: samsung model: mobile
vendor: samsung model: samsung
vendor: samsung model: notes
vendor: samsung model: note
vendor: huawei model: huawei
db: NVD ids: CVE-2024-47892, CVE-2023-40135, CVE-2025-0098, CVE-2023-40137, CVE-2024-20141, CVE-2025-0094, CVE-2024-49723, CVE-2025-0015, CVE-2024-38404, CVE-2024-43705, CVE-2024-20142, CVE-2024-53104, CVE-2024-49721, CVE-2024-52935, CVE-2024-38420, CVE-2025-0099, CVE-2025-0088, CVE-2023-40134, CVE-2025-0091, CVE-2024-49746, CVE-2023-40136, CVE-2024-46973, CVE-2023-40133, CVE-2025-20634, CVE-2024-0037, CVE-2025-0096, CVE-2024-49741, CVE-2023-40122, CVE-2024-39441, CVE-2025-0097, CVE-2024-49743, CVE-2024-49729, CVE-2025-20636, CVE-2025-20635, CVE-2023-40138, CVE-2023-40139, CVE-2025-0095, CVE-2025-0100

Trust: 3.75

Fetched: Feb. 7, 2025, 9:08 a.m., Published: Feb. 5, 2025, 11:50 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: google model: pixel
vendor: google model: android
vendor: samsung model: samsung
db: NVD ids: CVE-2022-22706, CVE-2021-39793

Trust: 4.0

Fetched: Feb. 7, 2025, 9:07 a.m., Published: Feb. 7, 2020, midnight
Vulnerabilities: password guessing
Affected productsExternal IDs
vendor: baxter model: prismaflex

Trust: 5.75

Fetched: Feb. 7, 2025, 9:06 a.m., Published: Jan. 30, 2025, 3:38 p.m.
Vulnerabilities: memory corruption, buffer overflow
Affected productsExternal IDs
vendor: google model: wi-fi router
db: NVD ids: CVE-2024-12649, CVE-2024-12648, CVE-2024-12647

Trust: 3.5

Fetched: Feb. 5, 2025, 9:35 a.m., Published: Feb. 5, 2025, 4:50 a.m.
Vulnerabilities: cross-site scripting, code execution, authentication bypass
Affected productsExternal IDs
vendor: netgear model: n300
vendor: netgear model: wnr614
vendor: netgear model: xr500 firmware
vendor: netgear model: netgear router
vendor: netgear model: router
vendor: netgear model: xr500

Trust: 5.0

Fetched: Feb. 5, 2025, 9:34 a.m., Published: Jan. 15, 2025, 12:02 a.m.
Vulnerabilities: authentication bypass
Affected productsExternal IDs
vendor: node.js model: node.js
db: NVD ids: CVE-2024-55591

Trust: 5.0

Fetched: Feb. 5, 2025, 9:33 a.m., Published: Feb. 1, 2025, midnight
Vulnerabilities: session hijacking, cross-site request forgery, request forgery
Affected productsExternal IDs
db: NVD ids: CVE-2025-23673

Trust: 6.5

Fetched: Feb. 5, 2025, 9:32 a.m., Published: Jan. 31, 2025, midnight
Vulnerabilities: input validation vulnerability, authentication bypass, request forgery...
Affected productsExternal IDs
vendor: apple model: cups
vendor: teltonika model: rut9xx
vendor: teltonika model: rut9xx routers
vendor: fortigate model: fortios
vendor: cups model: cups
vendor: sonicwall model: sma1000
db: NVD ids: CVE-2022-25168, CVE-2024-41710, CVE-2021-38647, CVE-2021-26084, CVE-2018-10561, CVE-2022-24847, CVE-2022-40684, CVE-2021-27905, CVE-2024-47176, CVE-2024-40891, CVE-2022-41040, CVE-2022-30023, CVE-2021-41773, CVE-2025-23006, CVE-2023-46747, CVE-2022-31137, CVE-2023-23752, CVE-2022-47945, CVE-2023-26801, CVE-2025-24085, CVE-2018-10562, CVE-2022-22947, CVE-2023-38646, CVE-2018-17532, CVE-2021-26086

Trust: 4.5

Fetched: Feb. 5, 2025, 9:30 a.m., Published: Feb. 4, 2025, 9:35 p.m.
Vulnerabilities: default credentials, command injection
Affected productsExternal IDs
db: NVD ids: CVE-2024-40891, CVE-2025-0890

Trust: 5.5

Fetched: Feb. 5, 2025, 9:29 a.m., Published: Feb. 4, 2025, 12:41 p.m.
Vulnerabilities: memory corruption, denial of service, code execution...
Affected productsExternal IDs
vendor: google model: android
db: NVD ids: CVE-2025-0099, CVE-2024-45569, CVE-2025-0097, CVE-2025-0103, CVE-2025-0108, CVE-2025-0111, CVE-2024-39441, CVE-2024-53104, CVE-2024-49721, CVE-2025-0104, CVE-2025-0098
Related entries in the VARIoT vulnerabilities database: VAR-202503-2605

Trust: 4.75

Fetched: Feb. 5, 2025, 9:28 a.m., Published: Feb. 5, 3788, midnight
Vulnerabilities: code execution, buffer overflow
Affected productsExternal IDs
db: NVD ids: CVE-2024-57440

Trust: 6.0

Fetched: Feb. 5, 2025, 9:28 a.m., Published: Feb. 4, 2025, 2:10 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: google model: android
db: NVD ids: CVE-2024-53104

Trust: 4.5

Fetched: Feb. 5, 2025, 9:27 a.m., Published: Jan. 23, 2025, 8:20 a.m.
Vulnerabilities: certificate validation vulnerability, command execution, path traversal
Affected productsExternal IDs
vendor: mitel model: micollab
vendor: sonicwall model: ssl vpn
vendor: sonicwall model: secure mobile access
vendor: sonicwall model: sma1000
vendor: sonicwall model: remote access
db: NVD ids: CVE-2025-23006, CVE-2024-55550, CVE-2024-41713, CVE-2024-48865

Trust: 4.5

Fetched: Feb. 5, 2025, 9:27 a.m., Published: Feb. 4, 2025, 11:40 a.m.
Vulnerabilities: memory corruption, privilege escalation, code execution...
Affected productsExternal IDs
vendor: google model: android
db: NVD ids: CVE-2025-0135, CVE-2024-45569, CVE-2025-0100, CVE-2025-0110, CVE-2025-0102, CVE-2025-0120, CVE-2025-0109, CVE-2025-0121, CVE-2025-0118, CVE-2025-0106, CVE-2025-0125, CVE-2025-0108, CVE-2025-0128, CVE-2025-0117, CVE-2025-0105, CVE-2025-0114, CVE-2025-0123, CVE-2025-0124, CVE-2025-0129, CVE-2025-0130, CVE-2025-0126, CVE-2025-0132, CVE-2025-0104, CVE-2025-0098, CVE-2025-0099, CVE-2025-0097, CVE-2025-0119, CVE-2025-0113, CVE-2024-39441, CVE-2025-0088, CVE-2025-0107, CVE-2025-0115, CVE-2025-0131, CVE-2024-53104, CVE-2025-0122, CVE-2025-0133, CVE-2025-0103, CVE-2025-0111, CVE-2025-0127, CVE-2025-0134, CVE-2025-0112, CVE-2025-0116, CVE-2025-0101, CVE-2024-49721, CVE-2024-51567

Trust: 4.5

Fetched: Feb. 5, 2025, 9:24 a.m., Published: Jan. 31, 2025, 2 p.m.
Vulnerabilities: code execution, denial of service
Affected productsExternal IDs
vendor: sony model: camera

Trust: 5.0

Fetched: Feb. 5, 2025, 9:23 a.m., Published: Feb. 4, 2025, midnight
Vulnerabilities: privilege escalation
Affected productsExternal IDs
vendor: google model: android

Trust: 3.75

Fetched: Feb. 5, 2025, 9:23 a.m., Published: Feb. 4, 2025, 7:19 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: samsung model: samsung mobile
vendor: samsung model: samsung
vendor: samsung model: mobile
db: NVD ids: CVE-2025-20882

Trust: 4.5

Fetched: Feb. 5, 2025, 9:17 a.m., Published: May 5, 2025, midnight
Vulnerabilities: information disclosure, denial of service
Affected productsExternal IDs
vendor: schneider model: bmxnor0200h
vendor: schneider model: control expert
vendor: schneider model: software update
vendor: schneider model: m340
vendor: schneider model: bmxnoe0100
vendor: schneider model: modicon m340
vendor: schneider model: modicon m340 bmxnoe0100
vendor: schneider electric model: bmxnor0200h
vendor: schneider electric model: control expert
vendor: schneider electric model: software update
vendor: schneider electric model: m340
vendor: schneider electric model: bmxnoe0100
vendor: schneider electric model: modicon m340
vendor: schneider electric model: modicon m340 bmxnoe0100
db: NVD ids: CVE-2024-12142

Trust: 3.75

Fetched: Feb. 5, 2025, 9:16 a.m., Published: Feb. 4, 2025, midnight
Vulnerabilities: default credentials, command injection
Affected productsExternal IDs
db: NVD ids: CVE-2024-40891, CVE-2024-40890, CVE-2025-0890

Trust: 5.5

Fetched: Feb. 5, 2025, 9:11 a.m., Published: Feb. 4, 2025, 4:28 p.m.
Vulnerabilities: privilege escalation, buffer overflow
Affected productsExternal IDs
vendor: google model: android
db: NVD ids: CVE-2024-53104