VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-201812-0114 CVE-2018-15001 Vivo V7 Android Vulnerability related to information disclosure from log files on devices CVSS V2: 2.1
CVSS V3: 5.5
Severity: MEDIUM
The Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys contains a platform app with a package name of com.vivo.bsptest (versionCode=1, versionName=1.0) containing an exported activity app component named com.vivo.bsptest.BSPTestActivity that allows any app co-located on the device to initiate the writing of the logcat log, bluetooth log, and kernel log to external storage. When logging is enabled, there is a notification in the status bar, so it is not completely transparent to the user. The user can cancel the logging, but it can be re-enabled since the app with a package name of com.vivo.bsptest cannot be disabled. The writing of these logs can be initiated by an app co-located on the device, although the READ_EXTERNAL_STORAGE permission is necessary to for an app to access the log files. The Vivo V7 is a smartphone from China's Vivo mobile communications company. com.vivo.bsptest.BSPTestActivity of the com.vivo.bsptest data package of the platform application in Vivo V7 (the Build fingerprint used is vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys) A security vulnerability exists in an application component. Attackers can exploit this vulnerability to write logcat logs, bluetooth logs, and kernel logs to external storage
VAR-201812-0113 CVE-2018-14998 Leagoo P1 Android Vulnerabilities related to authorization, authority, and access control in devices CVSS V2: 7.2
CVSS V3: 6.8
Severity: MEDIUM
The Leagoo P1 Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a hidden root privilege escalation capability to achieve command execution as the root user. They have made modifications that allow a user with physical access to the device to obtain a root shell via ADB by modifying read-only system properties at runtime. Specifically, modifying the ro.debuggable and the ro.secure system properties to a certain value and then restarting the ADB daemon allows for a root shell to be obtained via ADB. Leagoo P1 Android Devices have vulnerabilities related to authorization, permissions, and access control.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Leagoo P1 is a smart phone based on Android platform produced by Leagoo Malaysia. There is a security vulnerability in Leagoo P1 (the Build fingerprint used is sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys). An attacker in close physical proximity could exploit this vulnerability to execute commands as the root user
VAR-201812-0373 CVE-2018-15333 BIG-IP Vulnerable to unlimited upload of dangerous types of files CVSS V2: 2.1
CVSS V3: 5.5
Severity: MEDIUM
On versions 11.2.1. and greater, unrestricted Snapshot File Access allows BIG-IP system's user with any role, including Guest Role, to have access and download previously generated and available snapshot files on the BIG-IP configuration utility such as QKView and TCPDumps. BIG-IP Contains a vulnerability related to unlimited uploads of dangerous types of files.Information may be obtained. F5 BIG-IP is prone to an arbitrary file-access vulnerability. An attacker can exploit this issue to retrieve or delete arbitrary files, which may aid in further attacks. F5 BIG-IP is an all-in-one network device integrated with network traffic management, application security management, load balancing and other functions from F5 Corporation of the United States. The following versions are affected: F5 BIG-IP version 14.0.0 to 14.1.0, 13.0.0 to 13.1.1, 12.1.0 to 12.1.4, 11.2.1 to 11.6.3
VAR-201812-1157 CVE-2018-20577 Orange Livebox Cross-Site Request Forgery Vulnerability CVSS V2: 9.4
CVSS V3: 9.1
Severity: CRITICAL
Orange Livebox 00.96.320S devices allow cgi-bin/restore.exe, cgi-bin/firewall_SPI.exe, cgi-bin/setup_remote_mgmt.exe, cgi-bin/setup_pass.exe, and cgi-bin/upgradep.exe CSRF. This is related to Firmware 01.11.2017-11:43:44, Boot v0.70.03, Modem 5.4.1.10.1.1A, Hardware 02, and Arcadyan ARV7519RW22-A-L T VR9 1.2. Orange Livebox Contains a cross-site request forgery vulnerability.Tampering with information and disrupting service operations (DoS) There is a possibility of being put into a state. The OrangeLivebox is an ADSL (Asymmetric Digital Subscriber Line) modem. A cross-site request forgery vulnerability exists in multiple files in the OrangeLivebox00.96.320S version (Firmware00.96.320S version, Bootv0.70.03 version, Modem5.4.1.10.1.1A version, Hardware02 version, and ArcadyanARV7519RW22-A-LTVR91.2 version). A remote attacker can exploit this vulnerability to tamper with all configuration parameters. (Multiple files include: cgi-bin/restore.exe, cgi-bin/firewall_SPI.exe, cgi-bin/setup_remote_mgmt.exe, cgi-bin/setup_pass.exe and cgi-bin/upgradep.exe files)
VAR-201812-1156 CVE-2018-20576 Orange Livebox Vulnerable to cross-site request forgery CVSS V2: 5.8
CVSS V3: 5.4
Severity: MEDIUM
Orange Livebox 00.96.320S devices allow cgi-bin/autodialing.exe and cgi-bin/phone_test.exe CSRF, leading to arbitrary outbound telephone calls to an attacker-specified telephone number. This is related to Firmware 01.11.2017-11:43:44, Boot v0.70.03, Modem 5.4.1.10.1.1A, Hardware 02, and Arcadyan ARV7519RW22-A-L T VR9 1.2. Orange Livebox Contains a cross-site request forgery vulnerability.Information may be obtained and information may be altered. The OrangeLivebox is an ADSL (Asymmetric Digital Subscriber Line) modem. Cgi-bin/autodialing.exe and cgi- in the OrangeLivebox00.96.320S version (Firmware00.96.320S version, Bootv0.70.03 version, Modem5.4.1.10.1.1A version, Hardware02 version and ArcadyanARV7519RW22-A-LTVR91.2 version) A cross-site request forgery vulnerability exists in the bin/phone_test.exe file. A remote attacker can exploit this vulnerability to arbitrarily dial the phone number specified by the attacker
VAR-201901-1299 CVE-2018-20326 PLC Wireless Router GPN2.4P21-C-CN Cross-Site Scripting Vulnerability CVSS V2: 4.3
CVSS V3: 6.1
Severity: MEDIUM
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage=html/index.html var:subpage parameter. A cross-site scripting vulnerability exists in PLCWirelessRouterGPN2.4P21-C-CN that can be exploited by remote attackers to obtain sensitive information
VAR-201812-1155 CVE-2018-20575 Orange Livebox Input validation vulnerability CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
Orange Livebox 00.96.320S devices have an undocumented /system_firmwarel.stm URI for manual firmware update. This is related to Firmware 01.11.2017-11:43:44, Boot v0.70.03, Modem 5.4.1.10.1.1A, Hardware 02, and Arcadyan ARV7519RW22-A-L T VR9 1.2. Orange Livebox Contains an input validation vulnerability.Information may be tampered with. The Orange Livebox is an ADSL (Asymmetric Digital Subscriber Line) modem. An attacker could exploit this vulnerability to manually update the firmware
VAR-201812-0117 CVE-2018-15005 ZTE ZMAX Champ Android Vulnerabilities related to authorization, authority, and access control in devices CVSS V2: 5.6
CVSS V3: 7.1
Severity: HIGH
The ZTE ZMAX Champ Android device with a build fingerprint of ZTE/Z917VL/fortune:6.0.1/MMB29M/20170327.120922:user/release-keys contains a pre-installed platform app with a package name of com.zte.zdm.sdm (versionCode=31, versionName=V5.0.3) that contains an exported broadcast receiver app component named com.zte.zdm.VdmcBroadcastReceiver that allows any app co-located on the device to programmatically initiate a factory reset. In addition, the app initiating the factory reset does not require any permissions. A factory reset will remove all user data and apps from the device. This will result in the loss of any data that have not been backed up or synced externally. The capability to perform a factory reset is not directly available to third-party apps (those that the user installs themselves with the exception of enabled Mobile Device Management (MDM) apps), although this capability can be obtained by leveraging an unprotected app component of a pre-installed platform app. ZTE ZMAX Champ Android Devices have vulnerabilities related to authorization, permissions, and access control.Tampering with information and disrupting service operations (DoS) There is a possibility of being put into a state. ZTE ZMAX is prone to the following security vulnerabilities: 1. An arbitrary command-execution vulnerability 2. A denial-of-service vulnerability An attacker can exploit these issues by enticing a legitimate user to use the vulnerable application to execute arbitrary commands, to cause an affected device to crash, denying service to legitimate users. ZTE ZMAX Champ is a smartphone based on the Android platform of China's ZTE Corporation (ZTE). The com.zte.zdm.sdm data package of the pre-installed platform application in ZTE ZMAX Champ (the Build fingerprint used is ZTE/Z917VL/fortune: 6.0.1/MMB29M/20170327.120922: user/release-keys) There is a security vulnerability in the .zte.zdm.VdmcBroadcastReceiver component
VAR-201812-0123 CVE-2018-14979 ASUS ZenFone 3 Max Android Information disclosure vulnerabilities in devices CVSS V2: 1.9
CVSS V3: 4.7
Severity: MEDIUM
The ASUS ZenFone 3 Max Android device with a build fingerprint of asus/US_Phone/ASUS_X008_1:7.0/NRD90M/US_Phone-14.14.1711.92-20171208:user/release-keys contains a pre-installed app with a package name of com.asus.loguploader (versionCode=1570000275, versionName=7.0.0.55_170515). This app contains an exported service app component named com.asus.loguploader.LogUploaderService that, when accessed with a particular action string, will write a bugreport (kernel log, logcat log, and the state of system services including the text of active notifications), Wi-Fi Passwords, and other system data to external storage (sdcard). Any app with the READ_EXTERNAL_STORAGE permission on this device can read this data from the sdcard after it has been dumped there by the com.asus.loguploader. Third-party apps are not allowed to directly create a bugreport or access the user's stored wireless network credentials. Attackers can use the vulnerability to write vulnerability reports (kernel logs, logcat logs, and activity notification texts and other system service status), Wi-Fi passwords, and other system data to the SD card
VAR-201812-0111 CVE-2018-14992 ASUS ZenFone 3 Max Android Vulnerabilities related to security functions in devices CVSS V2: 2.1
CVSS V3: 5.5
Severity: MEDIUM
The ASUS ZenFone 3 Max Android device with a build fingerprint of asus/US_Phone/ASUS_X008_1:7.0/NRD90M/US_Phone-14.14.1711.92-20171208:user/release-keys contains a pre-installed platform app with a package name of com.asus.dm (versionCode=1510500200, versionName=1.5.0.40_171122) has an exposed interface in an exported service named com.asus.dm.installer.DMInstallerService that allows any app co-located on the device to use its capabilities to download an arbitrary app over the internet and install it. Any app on the device can send an intent with specific embedded data that will cause the com.asus.dm app to programmatically download and install the app. For the app to be downloaded and installed, certain data needs to be provided: download URL, package name, version name from the app's AndroidManifest.xml file, and the MD5 hash of the app. Moreover, any app that is installed using this method can also be programmatically uninstalled using the same unprotected component named com.asus.dm.installer.DMInstallerService. ASUS ZenFone 3 Max Android The device contains vulnerabilities related to security functions.Information may be tampered with. Attackers can use this vulnerability to download and install any application via the Internet
VAR-201812-0374 CVE-2018-15334 APM webtop Vulnerable to cross-site request forgery CVSS V2: 4.3
CVSS V3: 4.3
Severity: MEDIUM
A cross-site request forgery (CSRF) vulnerability in the APM webtop 11.2.1 or greater may allow attacker to force an APM webtop session to log out and require re-authentication. F5 BIG-IP APM is prone to a cross-site request-forgery vulnerability because the application fails to properly validate HTTP requests. An attacker can exploit this issue to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible. The following versions of BIG-IP APM are vulnerable: 14.0.0 through 14.1.0 13.0.0 through 13.1.1 12.1.0 through 12.1.3 11.5.1 through 11.6.3. F5 BIG-IP Access Policy Manager (APM) is a set of access and security solutions from F5 Corporation of the United States. The solution provides unified access to business-critical applications and networks. APM webtop is one of the access portals
VAR-201812-0242 CVE-2018-15335 APM Authorization vulnerability CVSS V2: 4.3
CVSS V3: 5.9
Severity: MEDIUM
When APM 13.0.0-13.1.x is deployed as an OAuth Resource Server, APM becomes a client application to an external OAuth authorization server. In certain cases when communication between the BIG-IP APM and the OAuth authorization server is lost, APM may not display the intended message in the failure response. APM Contains an authorization vulnerability.Information may be obtained. F5 BIG-IP APM is prone to a remote denial-of-service vulnerability. An attacker can exploit this issue to cause a denial-of-service condition. BIG-IP APM 13.0.0 through 13.1.1 are vulnerable. F5 BIG-IP Access Policy Manager (APM) is a set of access and security solutions from F5 Corporation of the United States. The solution provides unified access to business-critical applications and networks. Attackers can exploit this vulnerability to prevent APM from displaying correct information
VAR-201812-0140 CVE-2018-17539 ZebOS and OcNOS Input validation vulnerability CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
The BGP daemon (bgpd) in all IP Infusion ZebOS versions to 7.10.6 and all OcNOS versions to 1.3.3.145 allow remote attackers to cause a denial of service attack via an autonomous system (AS) path containing 8 or more autonomous system number (ASN) elements. ZebOS and OcNOS Contains an input validation vulnerability.Service operation interruption (DoS) There is a possibility of being put into a state. F5 BIG-IP ARM BGP is prone to a remote denial-of-service vulnerability. An attacker can exploit this issue to cause a denial-of-service condition. The following versions of BIG-IP ARM BGP are vulnerable: 14.0.0, 13.0.0 through 13.1.1, 12.1.0 through 12.1.3, 11.2.1 through 11.6.3. Both IP Infusion ZebOS and OcNOS are products of the US IP Infusion company. IP Infusion ZebOS is a standards-based layer 2, layer 3 and MPLS/MPLS/TP networking platform. OcNOS is a full-featured network operating system for White Box. A security vulnerability exists in the BGP daemon (bgpd) in IP Infusion ZebOS 7.10.6 and earlier and OcNOS 1.3.3.145 and earlier
VAR-201812-0306 CVE-2018-1000625 Battelle V2I Hub Vulnerabilities related to the use of hard-coded credentials CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
Battelle V2I Hub 2.5.1 contains hard-coded credentials for the administrative account. An attacker could exploit this vulnerability to log in as an admin on any installation and gain unauthorized access to the system. Battelle V2I Hub Contains a vulnerability in the use of hard-coded credentials.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state
VAR-201812-0418 CVE-2018-0724 Q'center Virtual Appliance Vulnerable to cross-site scripting CVSS V2: 4.3
CVSS V3: 6.1
Severity: MEDIUM
Cross-site scripting (XSS) vulnerability in Q'center Virtual Appliance 1.8.1014 and earlier versions could allow remote attackers to inject Javascript code in the compromised application, a different vulnerability than CVE-2018-0723. This vulnerability CVE-2018-0723 Is a different vulnerability.Information may be obtained and information may be altered
VAR-201812-0417 CVE-2018-0723 Q'center Virtual Appliance Vulnerable to cross-site scripting CVSS V2: 4.3
CVSS V3: 6.1
Severity: MEDIUM
Cross-site scripting (XSS) vulnerability in Q'center Virtual Appliance 1.8.1014 and earlier versions could allow remote attackers to inject Javascript code in the compromised application, a different vulnerability than CVE-2018-0724. This vulnerability CVE-2018-0724 Is a different vulnerability.Information may be obtained and information may be altered. QNAPQ'centerVirtualAppliance is a virtual device used by QNAP Systems to deploy Q'center (QNAPNAS management platform) in virtual environments such as Microsoft Hyper-V, VMware ESXi and Workstation
VAR-201812-0714 CVE-2018-20404 VIA Technologies EPIA-E900 Input validation vulnerability CVSS V2: 7.8
CVSS V3: 7.5
Severity: HIGH
ETK_E900.sys, a SmartETK driver for VIA Technologies EPIA-E900 system board, is vulnerable to denial of service attack via IOCTL 0x9C402048, which calls memmove and constantly fails on an arbitrary (uncontrollable) address, resulting in an eternal hang or a BSoD. VIA Technologies EPIA-E900 Contains an input validation vulnerability.Service operation interruption (DoS) There is a possibility of being put into a state. VIA Technologies EPIA-E900 system board is an embedded Pico-ITX motherboard from VIA Technologies. ETK_E900.sys SmartETK driver is one of the drivers. A security vulnerability exists in the ETK_E900.sys SmartETK driver for VIA Technologies EPIA-E900 system motherboards. An attacker could exploit this vulnerability to cause a denial of service
VAR-201812-0775 CVE-2018-20444 Technicolor CGA0111 Vulnerabilities related to certificate and password management in devices CVSS V2: 5.0
CVSS V3: 9.8
Severity: CRITICAL
Technicolor CGA0111 CGA0111E-ES-13-E23E-c8000r5712-170217-0829-TRU devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.4413.2.2.2.1.5.4.1.14.1.3.10001 and 1.3.6.1.4.1.4413.2.2.2.1.18.1.2.3.4.1.2.10001 SNMP requests. Technicolor CGA0111 The device contains vulnerabilities related to certificate and password management.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Technicolor CGA0111 is a cable modem of the French Technicolor Group. Technicolor CGA0111 CGA0111E-ES-13-E23E-c8000r5712-170217-0829-TRU has a security vulnerability
VAR-201812-0739 CVE-2018-20439 Technicolor DPC3928SL Vulnerabilities related to certificate and password management in devices CVSS V2: 5.0
CVSS V3: 9.8
Severity: CRITICAL
Technicolor DPC3928SL D3928SL-PSIP-13-A010-c3420r55105-170214a devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.4413.2.2.2.1.5.4.1.14.1.3.10001 and 1.3.6.1.4.1.4413.2.2.2.1.18.1.2.3.4.1.2.10001 SNMP requests. Technicolor DPC3928SL The device contains vulnerabilities related to certificate and password management.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Technicolor DPC3928SL is a cable modem of the French Technicolor Group. Technicolor DPC3928SL D3928SL-PSIP-13-A010-c3420r55105-170214a version has a security vulnerability
VAR-201812-0774 CVE-2018-20443 Technicolor TC7200.d1I Vulnerabilities related to certificate and password management in devices CVSS V2: 5.0
CVSS V3: 9.8
Severity: CRITICAL
Technicolor TC7200.d1I TC7200.d1IE-N23E-c7000r5712-170406-HAT devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.4413.2.2.2.1.5.4.1.14.1.3.10001 and 1.3.6.1.4.1.4413.2.2.2.1.18.1.2.3.4.1.2.10001 SNMP requests. Technicolor TC7200.d1I The device contains vulnerabilities related to certificate and password management.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Technicolor TC7200.d1I is a cable modem of the French Technicolor Group. Technicolor TC7200.d1I TC7200.d1IE-N23E-c7000r5712-170406-HAT has a security vulnerability