VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202502-3801 No CVE Konica Minolta (China) Investment Co., Ltd. MOBOTIX D25 has an unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Konica Minolta (China) Investment Co., Ltd. is a limited company whose main business is optical imaging, office equipment, medical and industrial equipment. Konica Minolta (China) Investment Co., Ltd. MOBOTIX D25 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202502-3816 No CVE Samsung ML-331x has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Samsung ML-331x is a laser printer. Samsung ML-331x has an unauthorized access vulnerability that can be exploited by attackers to obtain sensitive information.
VAR-202502-3782 No CVE Konica Minolta (China) Investment Co., Ltd. MOBOTIX v26 has an unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Konica Minolta (China) Investment Co., Ltd. is a limited company whose main business is optical imaging, office equipment, medical and industrial equipment. There is an unauthorized access vulnerability in MOBOTIX v26 of Konica Minolta (China) Investment Co., Ltd., which can be exploited by attackers to obtain sensitive information.
VAR-202502-3855 No CVE Mitsubishi Electric (China) Co., Ltd. Mitsubishi M70 BND-1000W022-K1 has industrial control equipment vulnerabilities CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
M70 BND-1000W022-K1 is a digital controller. Mitsubishi Electric (China) Co., Ltd. Mitsubishi M70 BND-1000W022-K1 has an industrial control device vulnerability, which can be exploited by attackers to cause denial of service.
VAR-202502-3820 No CVE Lexmark Information Technology (China) Co., Ltd. Lexmark MX331adn printer has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
The Lexmark MX331adn printer has functions such as single-sided automatic scanning, copying, faxing and touch screen. The Lexmark MX331adn printer of Lexmark Information Technology (China) Co., Ltd. has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202502-3845 No CVE Samsung C3060FR has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Samsung C3060FR is a high-performance color laser printer. Samsung C3060FR has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202502-3810 No CVE Ricoh Company, Ltd. SP 230SFNw has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Ricoh Company, Ltd. SP 230SFNw is an all-in-one driver. Ricoh Company, Ltd. SP 230SFNw has an unauthorized access vulnerability that can be exploited by attackers to obtain sensitive information.
VAR-202502-3819 No CVE Lexmark MC2535adwe has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Lexmark MC2535adwe is a color multifunction laser printer. Lexmark MC2535adwe has an unauthorized access vulnerability that can be exploited by attackers to obtain sensitive information.
VAR-202502-3817 No CVE Shenzhen Jixiang Tengda Technology Co., Ltd. A18 has a binary vulnerability CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
Shenzhen Jixiang Tengda Technology Co., Ltd. A18 is a 1200M WiFi 5 signal amplifier. Shenzhen Jixiang Tengda Technology Co., Ltd. A18 has a binary vulnerability that can be exploited by attackers to cause a denial of service.
VAR-202502-3818 No CVE Fujifilm Business Innovation (China) Co., Ltd. Xerox(R) C325 Color MFP has an unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Xerox(R) C325 Color MFP is an office device that integrates multiple functions such as printing, copying, scanning and faxing. Fujifilm Business Innovation (China) Co., Ltd. Xerox(R) C325 Color MFP has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202502-3802 No CVE Toshiba Corporation. e-STUDIO2515AC has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
e-STUDIO2515AC is a multifunctional color digital MFP. Toshiba Corporation. e-STUDIO2515AC has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202502-3783 No CVE Beijing Topsec Technology Co., Ltd.'s Internet Behavior Management has a command execution vulnerability CVSS V2: 7.1
CVSS V3: -
Severity: HIGH
Beijing Topsec Technology Co., Ltd. is an information security product and service solution provider. Beijing Topsec Technology Co., Ltd. has a command execution vulnerability in its online behavior management, which can be exploited by attackers to execute arbitrary commands.
VAR-202502-3793 No CVE HP LaserJet Pro MFP M128fn and HP LaserJet MFP M233sdw have unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
HP LaserJet Pro MFP M128fn and HP LaserJet MFP M233sdw are both printer products. HP LaserJet Pro MFP M128fn and HP LaserJet MFP M233sdw have an unauthorized access vulnerability that can be exploited by attackers to obtain sensitive information.
VAR-202502-3856 No CVE Hanwha Vision Co., Ltd. Wisenet Webviewer has an unauthorized access vulnerability CVSS V2: 6.4
CVSS V3: -
Severity: MEDIUM
Wisenet Webviewer is a webcam. Hanwha Vision Co., Ltd. Wisenet Webviewer has an unauthorized access vulnerability that can be exploited by attackers to obtain sensitive information.
VAR-202502-3780 No CVE Fujifilm (China) Investment Co., Ltd. DocuCentre-V C2265 has a command execution vulnerability CVSS V2: 8.5
CVSS V3: -
Severity: HIGH
DocuCentre-V C2265 is a digital multifunction printer. There is a command execution vulnerability in DocuCentre-V C2265 of Fujifilm (China) Investment Co., Ltd. Attackers can use this vulnerability to execute printer commands, which may cause the printer to lose response, thus affecting the printing service.
VAR-202502-3814 No CVE TP-LINK TL-R473 has SSH weak password vulnerability CVSS V2: 7.6
CVSS V3: -
Severity: HIGH
TP-LINK TL-R473 is an enterprise VPN router. TP-LINK TL-R473 has a weak SSH password vulnerability, which can be exploited by attackers to gain control of the server.
VAR-202502-2685 No CVE Shenzhen Anjiaweishi Information Technology Co., Ltd. MC series cameras have unauthorized access vulnerabilities CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Shenzhen Anjia Vision Information Technology Co., Ltd. MC-A37 300 is a 3-megapixel camera. MC-A37P 300 is a 3-megapixel camera. MC-A85 800 is an 8-megapixel camera. MC-A52 500 is a 5-megapixel camera. MC-J30 is a 4-megapixel camera. MC-J40 500 is a 5-megapixel full-color camera. MC-A42P 400 is a 4-megapixel camera. Shenzhen Anjia Vision Information Technology Co., Ltd. MC-A37 300, MC-A37P 300, MC-A85 800, MC-A52 500, MC-J30, MC-J40 500, MC-A42P 400 have unauthorized access vulnerabilities, which can be exploited by attackers to obtain sensitive information.
VAR-202502-2287 No CVE FUJIFILM Corporation ApeosPort-IV C3370 has an unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
ApeosPort-IV C3370 is a color digital multifunction printer with multiple functions including copy, print, scan and fax (optional). FUJIFILM Corporation ApeosPort-IV C3370 has an unauthorized access vulnerability that can be exploited by attackers to obtain sensitive information.
VAR-202502-3256 No CVE Shenzhen Anjiaweishi Information Technology Co., Ltd. MC series cameras have arbitrary file download vulnerabilities CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Shenzhen Anjia Vision Information Technology Co., Ltd. MC-A37 300 is a 3-megapixel camera. MC-A37P 300 is a 3-megapixel camera. MC-A85 800 is an 8-megapixel camera. MC-A52 500 is a 5-megapixel camera. MC-J30 is a 4-megapixel camera. MC-J40 500 is a 5-megapixel full-color camera. MC-A42P 400 is a 4-megapixel camera. Shenzhen Anjia Vision Information Technology Co., Ltd. MC-A37 300, MC-A37P 300, MC-A85 800, MC-A52 500, MC-J30, MC-J40 500, MC-A42P 400 have arbitrary file download vulnerabilities, which can be exploited by attackers to obtain sensitive information.
VAR-202502-3854 No CVE TOTOLINK A3002R has a denial of service vulnerability CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
A3002R is a dual-band Gigabit port 5G wireless router. TOTOLINK A3002R has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service.