VARIoT news about IoT security

Trust: 4.5

Fetched: Nov. 25, 2025, 9:29 a.m., Published: Nov. 3, 2025, midnight
Vulnerabilities: code execution, memory corruption, privilege escalation
Affected productsExternal IDs
vendor: google model: pixel
vendor: google model: android
vendor: oneplus model: oneplus
vendor: oneplus model: 3
vendor: samsung model: samsung
db: NVD ids: CVE-2024-43047

Trust: 3.25

Fetched: Nov. 25, 2025, 9:29 a.m., Published: -
Vulnerabilities: configuration error
Affected productsExternal IDs

Trust: 4.0

Fetched: Nov. 25, 2025, 9:29 a.m., Published: Nov. 30, 0001, midnight
Vulnerabilities: command injection
Affected productsExternal IDs
db: NVD ids: CVE-2025-40591

Trust: 5.5

Fetched: Nov. 25, 2025, 9:28 a.m., Published: Nov. 19, 2025, 4:20 a.m.
Vulnerabilities: code execution, command injection, os command injection...
Affected productsExternal IDs
vendor: trend micro model: security
vendor: trend model: security
db: NVD ids: CVE-2025-58034, CVE-2025-64446

Trust: 5.5

Fetched: Nov. 25, 2025, 9:28 a.m., Published: Nov. 23, 2025, 4:07 p.m.
Vulnerabilities: path traversal, buffer overflow, authentication bypass...
Affected productsExternal IDs
vendor: sonicwall model: sonicos
vendor: sonicwall model: ssl-vpn
vendor: sonicwall model: sma 100
vendor: palo model: networks
vendor: palo model: pan-os
vendor: palo model: firewall
vendor: palo alto networks model: networks
vendor: palo alto networks model: pan-os
vendor: palo alto networks model: firewall
db: NVD ids: CVE-2025-32818, CVE-2025-0108, CVE-2025-40601

Trust: 5.0

Fetched: Nov. 25, 2025, 9:26 a.m., Published: Nov. 24, 2025, 5:47 p.m.
Vulnerabilities: os command injection, code execution, code injection...
Affected productsExternal IDs
vendor: google model: home
vendor: netgear model: router
vendor: tenda model: router
vendor: tenda model: ac15
vendor: tenda model: ac15 ac1900
vendor: d-link model: dir
vendor: d-link model: router
vendor: cisco model: linksys
vendor: cisco model: routers
vendor: cisco model: router
vendor: cisco model: series
vendor: motorola model: motorola
vendor: fortigate model: fortios
vendor: tp-link model: routers
vendor: tp-link model: gateway
db: NVD ids: CVE-2022-22947, CVE-2013-1599, CVE-2024-10914, CVE-2025-31324, CVE-2023-1381, CVE-2020-8958, CVE-2022-42475, CVE-2025-34043, CVE-2022-40619, CVE-2025-9528, CVE-2023-41011, CVE-2024-4577, CVE-2022-36553, CVE-2014-3206, CVE-2025-4008, CVE-2024-3721, CVE-2019-9082, CVE-2023-23333, CVE-2023-1389, CVE-2020-10987, CVE-2022-24847, CVE-2017-9841, CVE-2020-9054
Related entries in the VARIoT vulnerabilities database: VAR-202511-2413

Trust: 4.75

Fetched: Nov. 25, 2025, 9:25 a.m., Published: -
Vulnerabilities: path traversal
Affected productsExternal IDs
vendor: asus model: router
vendor: asus model: routers
vendor: asus model: asus
db: NVD ids: CVE-2025-59372
Related entries in the VARIoT vulnerabilities database: VAR-202511-2421

Trust: 5.5

Fetched: Nov. 25, 2025, 9:25 a.m., Published: -
Vulnerabilities: command injection, os command injection
Affected productsExternal IDs
vendor: asus model: router
vendor: asus model: asus
db: NVD ids: CVE-2025-59370
Related entries in the VARIoT vulnerabilities database: VAR-202511-2372

Trust: 5.75

Fetched: Nov. 25, 2025, 9:24 a.m., Published: -
Vulnerabilities: denial of service
Affected productsExternal IDs
vendor: asus model: router
vendor: asus model: routers
vendor: asus model: asus
db: NVD ids: CVE-2025-59368

Trust: 3.0

Fetched: Nov. 25, 2025, 9:24 a.m., Published: Nov. 25, 2025, 12:25 a.m.
Vulnerabilities: access control flaw, authentication flaw
Affected productsExternal IDs
db: NVD ids: CVE-2025-63207
Related entries in the VARIoT vulnerabilities database: VAR-202511-2373

Trust: 3.25

Fetched: Nov. 25, 2025, 9:24 a.m., Published: -
Vulnerabilities: path traversal
Affected productsExternal IDs
db: NVD ids: CVE-2025-12003

Trust: 4.5

Fetched: Nov. 25, 2025, 9:21 a.m., Published: Nov. 25, 2025, midnight
Vulnerabilities: denial of service, default credentials, command injection...
Affected productsExternal IDs
vendor: snort model: snort
vendor: tenda model: router
vendor: snort.org model: snort
vendor: wireshark model: wireshark

Trust: 3.25

Fetched: Nov. 25, 2025, 9:19 a.m., Published: Nov. 20, 2025, 6:32 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: google model: chrome

Trust: 4.75

Fetched: Nov. 23, 2025, 10:12 a.m., Published: Nov. 17, 2025, 6:02 a.m.
Vulnerabilities: use after free, code execution, buffer overflow
Affected productsExternal IDs
vendor: google model: android
db: NVD ids: CVE-2025-48530

Trust: 3.75

Fetched: Nov. 23, 2025, 10:11 a.m., Published: Nov. 18, 2025, midnight
Vulnerabilities: path traversal, command injection
Affected productsExternal IDs
db: NVD ids: CVE-2025-64446

Trust: 3.5

Fetched: Nov. 23, 2025, 10:10 a.m., Published: Nov. 5, 2025, 11:14 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: apple model: iphone
vendor: apple model: software update
vendor: apple model: watchos
vendor: apple model: safari
vendor: apple model: macos
vendor: apple model: ipad
vendor: apple model: watch
vendor: apple model: apple tv
db: NVD ids: CVE-2025-43442

Trust: 3.25

Fetched: Nov. 23, 2025, 10:10 a.m., Published: Nov. 21, 2025, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: google model: chrome

Trust: 6.75

Fetched: Nov. 23, 2025, 10:09 a.m., Published: Nov. 23, 2023, midnight
Vulnerabilities: authentication bypass
Affected productsExternal IDs
vendor: asus model: dsl-ac51
vendor: asus model: dsl-n16
vendor: asus model: router
vendor: asus model: dsl-ac750
vendor: asus model: asus
vendor: asus model: routers
db: NVD ids: CVE-2025-59367

Trust: 3.25

Fetched: Nov. 23, 2025, 10:09 a.m., Published: Nov. 12, 2025, 3:20 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: cisco model: firepower

Trust: 4.75

Fetched: Nov. 23, 2025, 10:09 a.m., Published: Nov. 21, 2025, 5:06 p.m.
Vulnerabilities: service disruption
Affected productsExternal IDs
vendor: pfsense model: pfsense
db: NVD ids: CVE-2025-13051