VARIoT IoT vulnerabilities database
| VAR-201812-0644 | CVE-2018-8920 | Synology DiskStation Manager Injection vulnerability |
CVSS V2: 6.5 CVSS V3: 7.2 Severity: HIGH |
Improper neutralization of escape vulnerability in Log Exporter in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to inject arbitrary content to have an unspecified impact by exporting an archive in CSV format. Synology DiskStation Manager (DSM) Contains an injection vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Synology DiskStation Manager (DSM) is an operating system developed by Synology for network storage servers (NAS). The operating system can manage data, documents, photos, music and other information. There is a security vulnerability in the Log Exporter in versions earlier than Synology DSM 6.1.6-15266. A remote attacker could exploit this vulnerability to inject arbitrary content
| VAR-201812-0643 | CVE-2018-8919 | Synology DiskStation Manager Vulnerable to information disclosure |
CVSS V2: 5.0 CVSS V3: 9.8 Severity: CRITICAL |
Information exposure vulnerability in SYNO.Core.Desktop.SessionData in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to steal credentials via unspecified vectors. Synology DiskStation Manager (DSM) Contains an information disclosure vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Synology DiskStation Manager (DSM) is an operating system developed by Synology for network storage servers (NAS). The operating system can manage data, documents, photos, music and other information. An information disclosure vulnerability exists in SYNO.Core.Desktop.SessionData in Synology DSM versions earlier than 6.1.6-15266
| VAR-201812-0641 | CVE-2018-8917 | Synology DiskStation Manager Vulnerable to cross-site scripting |
CVSS V2: 3.5 CVSS V3: 5.4 Severity: MEDIUM |
Cross-site scripting (XSS) vulnerability in info.cgi in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to inject arbitrary web script or HTML via the host parameter. Synology DiskStation Manager (DSM) Contains a cross-site scripting vulnerability.Information may be obtained and information may be altered. Synology DiskStation Manager (DSM) is an operating system developed by Synology for network storage servers (NAS). The operating system can manage data, documents, photos, music and other information
| VAR-201812-0671 | CVE-2018-20379 | Technicolor DPC3928SL Cross-Site Scripting Vulnerability |
CVSS V2: 2.6 CVSS V3: 4.7 Severity: MEDIUM |
Technicolor DPC3928SL D3928SL-PSIP-13-A010-c3420r55105-160428a devices allow XSS via a Cross Protocol Injection attack with setSSID of 1.3.6.1.4.1.4413.2.2.2.1.18.1.2.1.1.3.10001. Technicolor DPC3928SL The device contains a cross-site scripting vulnerability.Information may be obtained and information may be altered. The Technicolor DPC3928SL is a cable modem from the French Technicolor group. A remote attacker can exploit this vulnerability to inject arbitrary web scripts or HTML with the help of setSSID
| VAR-201812-0666 | CVE-2018-20373 | Tenda ADSL modem routers cross-site scripting vulnerability |
CVSS V2: 3.5 CVSS V3: 5.4 Severity: MEDIUM |
Tenda ADSL modem routers 1.0.1 allow XSS via the hostname of a DHCP client. TendaADSLmodemrouters is a wireless router from Tenda. A cross-site scripting vulnerability exists in the TendaADSLmodemrouters1.0.1 release. A remote attacker could exploit the vulnerability of a DHCP client to inject malicious code into the current list of DHCP clients
| VAR-201812-0665 | CVE-2018-20372 | TP-Link TD-W8961ND Cross-Site Scripting Vulnerability |
CVSS V2: 3.5 CVSS V3: 5.4 Severity: MEDIUM |
TP-Link TD-W8961ND devices allow XSS via the hostname of a DHCP client. TP-Link TD-W8961ND The device contains a cross-site scripting vulnerability.Information may be obtained and information may be altered. The TP-LinkTD-W8961ND is a wireless router from China Unicom (TP-LINK). A cross-site scripting vulnerability exists in the TP-LinkTD-W8961ND. A remote attacker can use the vulnerability of a DHCP client to inject malicious code into the current list of DHCP clients
| VAR-201812-0678 | CVE-2018-20386 | ARRIS SBG6580-2 Vulnerabilities related to certificate and password management in devices |
CVSS V2: 5.0 CVSS V3: 9.8 Severity: CRITICAL |
ARRIS SBG6580-2 D30GW-SEAEAGLE-1.5.2.5-GA-00-NOSH devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests. ARRIS SBG6580-2 The device contains vulnerabilities related to certificate and password management.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. ARRIS SBG6580-2 is a cable modem produced by Arris Group Corporation in the United States. A security vulnerability exists in ARRIS SBG6580-2 D30GW-SEAEAGLE-1.5.2.5-GA-00-NOSH version
| VAR-201812-0674 | CVE-2018-20382 | Jiuzhou BCM93383WRG Vulnerabilities related to certificate and password management in devices |
CVSS V2: 5.0 CVSS V3: 9.8 Severity: CRITICAL |
Jiuzhou BCM93383WRG 139.4410mp1.3921132mp1.899.004404.004 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests. Jiuzhou BCM93383WRG The device contains vulnerabilities related to certificate and password management.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Jiuzhou BCM93383WRG is a modem. There is a security vulnerability in Jiuzhou BCM93383WRG 139.4410mp1.3921132mp1.899.004404.004 version
| VAR-201812-0677 | CVE-2018-20385 | plural CastleNet Vulnerabilities related to certificate and password management in product devices |
CVSS V2: 5.0 CVSS V3: 9.8 Severity: CRITICAL |
plural CastleNet Product devices contain vulnerabilities related to certificate and password management.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. CastleNet CBV38Z4EC etc. are the cable modem products of CostleNet Technology Company. Security vulnerabilities exist in several CastleNet products. A remote attacker could exploit this vulnerability to obtain credentials by sending SNMP requests. The following products and versions are affected: CastleNet CBV38Z4EC version 125.553mp1.39219mp1.899.007; CBV38Z4ECNIT version 125.553mp1.39219mp1.899.005ITT; CBW383G4J version 37.556mp5.008; CBW38G4J version 17.0083
| VAR-201812-0672 | CVE-2018-20380 | plural Ambit Vulnerabilities related to certificate and password management in devices |
CVSS V2: 5.0 CVSS V3: 9.8 Severity: CRITICAL |
Ambit DDW2600 5.100.1009, DDW2602 5.105.1003, T60C926 4.64.1012, and U10C019 5.66.1026 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests. plural Ambit The device contains vulnerabilities related to certificate and password management.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Ambit DDW2600 etc. are all modem products. There are security vulnerabilities in several Ambit products. The following products and versions are affected: Ambit DDW2600 version 5.100.1009; DDW2602 version 5.105.1003; T60C926 version 4.64.1012; U10C019 version 5.66.1026
| VAR-201812-0676 | CVE-2018-20384 | iNovo Broadband IB-8120-W21 and IB-8120-W21E1 Vulnerabilities related to certificate and password management in devices |
CVSS V2: 5.0 CVSS V3: 9.8 Severity: CRITICAL |
iNovo Broadband IB-8120-W21 139.4410mp1.004200.002 and IB-8120-W21E1 139.4410mp1.3921132mp1.899.004404.004 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests. iNovo Broadband IB-8120-W21 and IB-8120-W21E1 The device contains vulnerabilities related to certificate and password management.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Both iNovo Broadband IB-8120-W21 and IB-8120-W21E1 are modem products. There are security vulnerabilities in iNovo Broadband IB-8120-W21 version 139.4410mp1.004200.002 and IB-8120-W21E1 version 139.4410mp1.3921132mp1.899.004404.004
| VAR-201812-0680 | CVE-2018-20388 | Comtrend CM-6200un and CM-6300n Vulnerabilities related to certificate and password management in devices |
CVSS V2: 5.0 CVSS V3: 9.8 Severity: CRITICAL |
Comtrend CM-6200un 123.447.007 and CM-6300n 123.553mp1.005 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests. Comtrend CM-6200un and CM-6300n The device contains vulnerabilities related to certificate and password management.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Both Comtrend CM-6200un and CM-6300n are cable modem products of Comtrend Company. There are security vulnerabilities in Comtrend CM-6200un 123.447.007 version and CM-6300n 123.553mp1.005 version
| VAR-201812-0679 | CVE-2018-20387 | plural Bnmux Vulnerabilities related to certificate and password management in products |
CVSS V2: 5.0 CVSS V3: 9.8 Severity: CRITICAL |
Bnmux BCW700J 5.20.7, BCW710J 5.30.6a, and BCW710J2 5.30.16 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests. Bnmux BCW700J , BCW710J , BCW710J2 The device contains vulnerabilities related to certificate and password management.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Bnmux BCW700J, BCW710J and BCW710J2 are all modem products of Japan Broad Net Mux (Bnmux) company. There are security vulnerabilities in Bnmux BCW700J version 5.20.7, BCW710J version 5.30.6a and BCW710J2 version 5.30.16
| VAR-201812-0673 | CVE-2018-20381 | Technicolor DPC2320 Vulnerabilities related to certificate and password management in devices |
CVSS V2: 5.0 CVSS V3: 9.8 Severity: CRITICAL |
Technicolor DPC2320 dpc2300r2-v202r1244101-150420a-v6 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests. Technicolor DPC2320 The device contains vulnerabilities related to certificate and password management.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Technicolor DPC2320 is a modem from Technicolor Group.
Technicolor DPC2320 dpc2300r2-v202r1244101-150420a-v6 has a security vulnerability
| VAR-201812-0675 | CVE-2018-20383 | ARRIS DG950A and DG950S Vulnerabilities related to certificate and password management in devices |
CVSS V2: 5.0 CVSS V3: 9.8 Severity: CRITICAL |
ARRIS DG950A 7.10.145 and DG950S 7.10.145.EURO devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests. ARRIS DG950A and DG950S The device contains vulnerabilities related to certificate and password management.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Both ARRIS DG950A and DG950S are cable modems from Arris Group Corporation in the United States. A security vulnerability exists in ARRIS DG950A version 7.10.145 and DG950S version 7.10.145.EURO
| VAR-201812-0687 | CVE-2018-20395 | NETWAVE MNG6200 Vulnerabilities related to certificate and password management in devices |
CVSS V2: 5.0 CVSS V3: 9.8 Severity: CRITICAL |
NETWAVE MNG6200 C4835805jrc12FU121413.cpr devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests. NETWAVE MNG6200 The device contains vulnerabilities related to certificate and password management.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. NETWAVE MNG6200 is a modem product. A security vulnerability exists in NETWAVE MNG6200 C4835805jrc12FU121413.cpr version
| VAR-201812-0683 | CVE-2018-20391 | TEKNOTEL CBW700N Vulnerabilities related to certificate and password management in devices |
CVSS V2: 5.0 CVSS V3: 9.8 Severity: CRITICAL |
TEKNOTEL CBW700N 81.447.392110.729.024 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests. TEKNOTEL CBW700N The device contains vulnerabilities related to certificate and password management.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. TEKNOTEL CBW700N is a modem. A security vulnerability exists in TEKNOTEL CBW700N version 81.447.392110.729.024
| VAR-201812-0708 | CVE-2018-20397 | mplus CBC383Z Vulnerabilities related to certificate and password management in devices |
CVSS V2: 5.0 CVSS V3: 9.8 Severity: CRITICAL |
mplus CBC383Z CBC383Z_mplus_MDr026 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests. mplus CBC383Z The device contains vulnerabilities related to certificate and password management.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. mplus CBC383Z is a modem product. A security vulnerability exists in mplus CBC383Z CBC383Z_mplus_MDr026 version
| VAR-201812-0684 | CVE-2018-20392 | S-A WebSTAR DPC2100 Vulnerabilities related to certificate and password management in devices |
CVSS V2: 5.0 CVSS V3: 9.8 Severity: CRITICAL |
S-A WebSTAR DPC2100 v2.0.2r1256-060303 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests. S-A WebSTAR DPC2100 The device contains vulnerabilities related to certificate and password management.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. SA WebSTAR DPC2100 is a modem. There is a security vulnerability in SA WebSTAR DPC2100 v2.0.2r1256-060303 version
| VAR-201812-0707 | CVE-2018-20396 | NET&SYS MNG2120J and MNG6300 Vulnerabilities related to certificate and password management in devices |
CVSS V2: 5.0 CVSS V3: 9.8 Severity: CRITICAL |
NET&SYS MNG2120J 5.76.1006c and MNG6300 5.83.6305jrc2 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests. NET&SYS MNG2120J and MNG6300 The device contains vulnerabilities related to certificate and password management.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. NET&SYS MNG2120J and MNG6300 are both cable modem products of Korea NET&SYS Company. A security vulnerability exists in NET&SYS MNG2120J version 5.76.1006c and MNG6300 version 5.83.6305jrc2