VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-201707-0327 CVE-2017-2235 Improper access control vulnerability in Toshiba Lighting & Technology Corporation Home gateway CVSS V2: 5.0
CVSS V3: 9.8
Severity: CRITICAL
Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier. Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier allows an attacker to bypass access restriction to change the administrator account password via unspecified vectors. Home gateway provided by Toshiba Lighting & Technology Corporation contains improper access control. Yutaka Kokubu of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.The administrator's password may be changed. There is an access control error vulnerability in TOSHIBAHomeGatewayHEM-GW26A using HEM-GW26A-FW-V1.2.0 and previous firmware and TOSHIBAHomeGatewayHEM-GW16A using HEM-GW16A-FW-V1.2.0 and previous firmware. An attacker could use this vulnerability to change the administrator password
VAR-201707-0328 CVE-2017-2236 Hard-coded credentials vulnerability in Toshiba Lighting & Technology Corporation Home gateway CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier, Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier uses hard-coded credentials, which may allow attackers to perform operations on device with administrative privileges. Yutaka Kokubu of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.The device is operated with the administrative privilege. There is a hard-coded voucher vulnerability in TOSHIBAHomeGatewayHEM-GW26A using HEM-GW26A-FW-V1.2.0 and previous firmware and TOSHIBAHomeGatewayHEM-GW16A using HEM-GW16A-FW-V1.2.0 and previous firmware. An attacker could exploit the vulnerability to perform operations with administrator privileges
VAR-201707-0329 CVE-2017-2237 OS command injection vulnerability in Toshiba Lighting & Technology Corporation Home gateway CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier. Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors. Yutaka Kokubu of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.An arbitrary OS command may be executed on the device. There is an operating system command injection vulnerability in TOSHIBAHomeGatewayHEM-GW26A using HEM-GW26A-FW-V1.2.0 and previous firmware and TOSHIBAHomeGatewayHEM-GW16A using HEM-GW16A-FW-V1.2.0 and previous firmware. An attacker could exploit this vulnerability to execute arbitrary operating system commands. Failed exploit attempts will result in a denial-of-service condition
VAR-201707-0330 CVE-2017-2238 Cross-site request forgery vulnerability in Toshiba Lighting & Technology Corporation Home gateway

Related entries in the VARIoT exploits database: VAR-E-201706-0398
CVSS V2: 6.8
CVSS V3: 8.8
Severity: HIGH
Cross-site request forgery (CSRF) vulnerability in Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier and Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. Yutaka Kokubu of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.The user may be tricked to perform unintended operation on the device. A remote attacker could exploit this vulnerability to perform unauthorized operations. Exploiting the issue will allow a remote attacker to use a victim's currently active session to hijack the authentication of administrators. Successful exploits will compromise affected device
VAR-201706-1195 No CVE ARRIS VAP2500 Default Credentials Remote Code Execution Vulnerability CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of ARRIS VAP2500. Authentication is not required to exploit this vulnerability.The specific flaw exists within the firmware and filesystem of the ARRIS VAP2500. The firmware and filesystem contain hard-coded default credentials in clear text. An attacker can leverage this vulnerability to execute code under the context of root.
VAR-201706-1191 No CVE ARRIS VAP2500 tools_command Command Injection Remote Code Execution Vulnerability CVSS V2: 9.0
CVSS V3: -
Severity: HIGH
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of ARRIS VAP2500. Authentication is required to exploit this vulnerability.The specific flaw exists within the handling of the parameters provided to the tools_command.php management portal page. The issue lies in the failure to properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code under the context of root.
VAR-201706-1193 No CVE ARRIS VAP2500 config_wds Command Injection Remote Code Execution Vulnerability CVSS V2: 9.0
CVSS V3: -
Severity: HIGH
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of ARRIS VAP2500. Authentication is required to exploit this vulnerability.The specific flaw exists within the handling of the various txt_mac parameters provided to the config_wds.php management portal page. The issue lies in the failure to properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code under the context of root.
VAR-201706-1188 No CVE ARRIS VAP2500 list_mac_address macaddr Command Injection Remote Code Execution Vulnerability CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of ARRIS VAP2500. Authentication is not required to exploit this vulnerability.The specific flaw exists within the handling of the macaddr parameter provided to the list_mac_address.php management portal page. The issue lies in the failure to properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code under the context of root.
VAR-201706-1190 No CVE ARRIS VAP2500 list_mac_address cmb_macaddrfilter Command Injection Remote Code Execution Vulnerability CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of ARRIS VAP2500. Authentication is not required to exploit this vulnerability.The specific flaw exists within the handling of the cmb_macaddrfilter parameter provided to the list_mac_address.php management portal page. The issue lies in the failure to properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code under the context of root.
VAR-201706-1141 No CVE dLAN 200 AVeasy has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
dLAN 200 AVeasy is a network device in Germany that transforms the home power grid into a convenient data network. dLAN 200 AVeasy has an unauthorized access vulnerability that allows an attacker to bypass permission authentication, access sensitive directories or files, and obtain sensitive information.
VAR-201808-0004 CVE-2016-4975 Cosminexus HTTP Server  and  Hitachi Web Server  Vulnerability in CVSS V2: 4.3
CVSS V3: 6.1
Severity: MEDIUM
Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32 which prohibit CR or LF injection into the "Location" or other outbound header key or value. Fixed in Apache HTTP Server 2.4.25 (Affected 2.4.1-2.4.23). Fixed in Apache HTTP Server 2.2.32 (Affected 2.2.0-2.2.31). Attackers can leverage this issue to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that try to entice client users into having a false sense of trust
VAR-201706-1185 No CVE ARRIS VAP2500 assoc_table Command Injection Remote Code Execution Vulnerability CVSS V2: 9.0
CVSS V3: -
Severity: HIGH
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of ARRIS VAP2500. Authentication is required to exploit this vulnerability.The specific flaw exists within the handling of the various txt_mac parameters provided to the config_wds.php management portal page. The issue lies in the failure to properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code under the context of root.
VAR-201706-1186 No CVE ARRIS VAP2500 list_mac_address Authentication Bypass Remote Code Execution Vulnerability CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of ARRIS VAP2500. Authentication is not required to exploit this vulnerability.The specific flaw exists within the authentication validation mechanism of the used in the list_mac_address.php management portal page. The issue lies in the failure to stop processing the page after an unsuccessful attempt to validate authentication. An attacker can leverage this vulnerability to execute code under the context of root.
VAR-201706-0017 CVE-2016-8493 fortinet's  Windows  for  FortiClient  Vulnerabilities related to authorization, privileges, and access control in CVSS V2: 9.0
CVSS V3: 8.8
Severity: HIGH
In FortiClientWindows 5.4.1 and 5.4.2, an attacker may escalate privilege via a FortiClientNamedPipe vulnerability. fortinet's Windows for FortiClient contains vulnerabilities related to authorization, privileges, and access control.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Fortinet FortiClient is prone to a privilege-escalation vulnerability. An attacker can exploit this issue to execute arbitrary code with elevated privileges. FortiClient 5.4.1 and 5.4.2 are vulnerable. Fortinet FortiClient is a mobile terminal security solution developed by Fortinet. The solution provides IPsec and SSL encryption, WAN optimization, endpoint compliance, and two-factor authentication when connected to FortiGate firewall appliances
VAR-201711-0981 CVE-2017-8143 Huawei Honor 5C and P9 Lite Vulnerability related to input validation in smartphone software CVSS V2: 7.1
CVSS V3: 5.5
Severity: MEDIUM
Wi-Fi driver of Honor 5C and P9 Lite Huawei smart phones with software versions earlier than NEM-L21C432B351 and versions earlier than VNS-L21C10B381 has a DoS vulnerability. An attacker may trick a user into installing a malicious application and the application can access invalid address of driver to crash the system. HuaweiHonor5C and P9Lite are both Huawei's smartphone products. Huawei's mobile Wi-Fi driver has a denial of service vulnerability. Huawei Smart Phones are prone to local denial-of-service vulnerability. Attackers can exploit this issue to crash the system, resulting in a denial-of-service condition
VAR-201706-1112 No CVE SQL injection vulnerability exists in the WSLoginMobile.asmx? wsdl parameter of the iOffice system CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
Hongfan iOffice system is based on Microsoft's .NET technology. It is a mobile information system based on portable terminals such as notebooks and mobile phones. There is a SQL injection vulnerability in the WSLoginMobile.asmx? wsdl parameter of the iOffice system. The vulnerability is caused by failure to effectively filter the data submitted by users, allowing attackers to use the vulnerability to obtain database sensitive information.
VAR-201706-1009 CVE-2017-9828 plural VIVOTEK Network Camera Product Web Service of /cgi-bin/admin/testserver.cgi Vulnerable to shell command insertion CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
'/cgi-bin/admin/testserver.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable to shell command injection, which allows remote attackers to execute any shell command as root via a crafted HTTP request. This vulnerability is already verified on VIVOTEK Network Camera IB8369/FD8164/FD816BA; most others have similar firmware that may be affected. An attack uses shell metacharacters in the senderemail parameter. VIVOTEKNetworkCameras IB8369, FD8164 and FD816BA are all network camera products of China VIVOTEK. A security vulnerability exists in the /cgi-bin/admin/testserver.cgi file for Web services in VIVOTEKNetworkCamerasIB8369, FD8164, and FD816BA
VAR-201706-1010 CVE-2017-9829 plural VIVOTEK Network Camera Product Web Service of /cgi-bin/admin/downloadMedias.cgi Vulnerable to reading arbitrary files CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
'/cgi-bin/admin/downloadMedias.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable, which allows remote attackers to read any file on the camera's Linux filesystem via a crafted HTTP request containing ".." sequences. This vulnerability is already verified on VIVOTEK Network Camera IB8369/FD8164/FD816BA; most others have similar firmware that may be affected. VIVOTEKNetworkCameras IB8369, FD8164 and FD816BA are all network camera products of China VIVOTEK
VAR-201706-0485 CVE-2017-2780 InsideSecure MatrixSSL Buffer error vulnerability CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially crafted x509 certificate can cause a buffer overflow on the heap resulting in remote code execution. To trigger this vulnerability, a specially crafted x509 certificate must be presented to the vulnerable client or server application when initiating secure connection. InsideSecure MatrixSSL Contains a buffer error vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Inside Secure MatrixSSL is an IoT application toolkit from the French company Inside Secure, which can implement TLS and DTLS in a modular way. MatrixSSL is prone to multiple buffer-overflow vulnerabilities. Failed exploit attempts will result in denial-of-service conditions. MatrixSSL 3.8.7b is vulnerable; other versions may also be affected
VAR-201706-0487 CVE-2017-2782 InsideSecure MatrixSSL Integer overflow vulnerability CVSS V2: 6.4
CVSS V3: 9.1
Severity: CRITICAL
An integer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially crafted x509 certificate can cause a length counter to overflow, leading to a controlled out of bounds copy operation. To trigger this vulnerability, a specially crafted x509 certificate must be presented to the vulnerable client or server application when initiating secure connection. InsideSecure MatrixSSL Contains an integer overflow vulnerability.Information is obtained and service operation is interrupted (DoS) There is a possibility of being put into a state. Inside Secure MatrixSSL is an IoT application toolkit from the French company Inside Secure, which can implement TLS and DTLS in a modular way. MatrixSSL is prone to multiple buffer-overflow vulnerabilities. Attackers can exploit these issues to execute arbitrary code in the context of the affected application. Failed exploit attempts will result in denial-of-service conditions. MatrixSSL 3.8.7b is vulnerable; other versions may also be affected