VARIoT IoT vulnerabilities database
| VAR-201706-1137 | No CVE | There is a Stack Overflow Vulnerability in the Connect Method of the Massa SoftNVR-IA NVRPB Control |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
Mosha Video Surveillance System SoftNVR-IA is a real-time IP video monitoring software developed by Mosha Technology (Shanghai) Co., Ltd.
There is a stack overflow vulnerability in the Connect method of the NVRPB ActiveX control of Mosha Video Surveillance System SoftNVR-IA. By tricking users into following specific links, an attacker can execute arbitrary code.
| VAR-201803-0208 | CVE-2017-17330 | Huawei AR3200 and NGFW Module Resource management vulnerability |
CVSS V2: 2.1 CVSS V3: 3.3 Severity: LOW |
Huawei AR3200 V200R005C32; V200R006C10; V200R006C11; V200R007C00; V200R007C01; V200R007C02; V200R008C00; V200R008C10; V200R008C20; V200R008C30; NGFW Module V500R001C00; V500R001C20; V500R002C00 have a memory leak vulnerability. The software does not release allocated memory properly when parse XML element data. An authenticated attacker could upload a crafted XML file, successful exploit could cause the system service abnormal since run out of memory. Huawei AR3200 and NGFW Module Contains a resource management vulnerability.Service operation interruption (DoS) There is a possibility of being put into a state. Huawei AR3200 and NGFWModule are products of China Huawei. HuaweiAR3200 is an AR3200 series enterprise router product. NGFWModule is a firewall product. Multiple Huawei products are prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause denial-of-service conditions. The following products and versions are affected: Huawei AR3200 V200R005C32 Version, V200R006C10 Version, V200R006C11 Version, V200R007C00 Version, V200R007C01 Version, V200R007C02 Version, V200R008C00 Version, V200R008C10 Version, V200R008C20 Version, V200R008C30 Version; NGFW Module V500R001C00 Version, V500R001C20 Version, V500R002C00 Version
| VAR-201706-0564 | CVE-2017-6685 | Cisco Ultra Services Framework Staging Server Vulnerable to logging in as an admin user on the affected device |
CVSS V2: 6.5 CVSS V3: 8.8 Severity: HIGH |
A vulnerability in Cisco Ultra Services Framework Staging Server could allow an authenticated, remote attacker with access to the management network to log in as an admin user of the affected device, aka an Insecure Default Credentials Vulnerability. More Information: CSCvc76681. Known Affected Releases: 21.0.0.
An attacker can exploit this issue to bypass the security mechanism and gain unauthorized access. This may lead to further attacks.
This issue is tracked by Cisco Bug ID CSCvc76681
| VAR-201706-0707 | CVE-2017-9542 | D-Link DIR-615 wireless N 300 Authentication vulnerabilities in routers |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
D-Link DIR-615 Wireless N 300 Router allows authentication bypass via a modified POST request to login.cgi. This issue occurs because it fails to validate the password field. Successful exploitation of this issue allows an attacker to take control of the affected device. The D-Link DIR-615 Wireless N300 is a wireless router product from D-Link. A security vulnerability exists in the D-LinkDIR-615 Wireless N300 router that originated from the program unverified password field. This may lead to further attacks
| VAR-201707-1025 | CVE-2017-9521 | plural Cisco DPC Products and Arris TG1682G Vulnerabilities related to security functions |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST); Cisco DPC3939B (firmware version dpc3939b-v303r204217-150321a-CMCST); Cisco DPC3941T (firmware version DPC3941_2.5s3_PROD_sey); and Arris TG1682G (eMTA&DOCSIS version 10.0.132.SIP.PC20.CT, software version TG1682_2.2p7s2_PROD_sey) devices allows remote attackers to execute arbitrary code via a specific (but unstated) exposed service. NOTE: the scope of this CVE does NOT include the concept of "Unnecessary Services" in general; the scope is only a single service that is unnecessarily exposed, leading to remote code execution. The details of that service might be disclosed at a later date. plural Cisco DPC Products and Arris TG1682G Contains vulnerabilities related to security features.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Cisco DPC3939 (XB3) and so on are Cisco's wireless home voice gateway products. The ArrisTG1682G is a modem product from Arris, USA. Comcast is a set of firmware developed by Comcast, Inc., which runs on gateways and modem devices. A remote attacker can exploit this vulnerability to execute arbitrary code
| VAR-201707-1026 | CVE-2017-9522 | Technicolor TC8717T Vulnerabilities related to security functions |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
The Time Warner firmware on Technicolor TC8717T devices sets the default Wi-Fi passphrase to a combination of the SSID and BSSID, which makes it easier for remote attackers to obtain network access by reading a beacon frame. Technicolor TC8717T Contains vulnerabilities related to security features.Information may be obtained. TechnicolorTC8717Tdevices is a router from Technicolor, France. TimeWarner is the firmware that runs in it. There is a security hole in the TimeWarner firmware on the TechnicolorTC8717T device. A remote attacker can exploit this vulnerability to gain network access by reading beacon frames
| VAR-201706-1143 | No CVE | Foscam camera FTP Server Account Empty Password Vulnerability |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
Foscamcamera is a webcam that can push messages to mobile phones and directly implement video Baidu cloud storage via WIFI. The Foscamcamera FTP server has an account blank password vulnerability. The password of the built-in FTP account of Foscam is empty by default, which can cause an attacker to upload and download files.
| VAR-201706-1147 | No CVE | Foscam camera ONVIF GetStreamUri Administrator Credential Disclosure Vulnerability |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
Foscamcamera is a webcam that can push messages to mobile phones and directly implement video Baidu cloud storage via WIFI. There is an administrator credential disclosure vulnerability in FoscamcameraONVIFGetStreamUri, and the Foscam camera device uses the interface of the ONVIF protocol to allow anonymous access. An unauthenticated attacker can extract the administrator username and password via the \"media\" GetStreamUri method. This vulnerability only exists in some devices or parts of the firmware version.
| VAR-201706-1140 | No CVE | Foscam camera anonymous ONVIF SetDNS remote command injection vulnerability |
CVSS V2: 7.5 CVSS V3: - Severity: HIGH |
Foscamcamera is a webcam that can push messages to mobile phones and directly implement video Baidu cloud storage via WIFI. Foscamcamera anonymous ONVIFSetDNS has a remote command injection vulnerability. The Foscam camera device uses the ONVIF protocol interface to allow anonymous access. An unauthenticated attacker can trigger remote command execution through the devicemgmtSetDNS method, and the command is executed as root. This particular vulnerability is very serious because it can be used without any credentials.
| VAR-201706-1135 | No CVE | Foscam camera Telnet feature vulnerability |
CVSS V2: 7.5 CVSS V3: - Severity: HIGH |
Foscamcamera is a webcam that can push messages to mobile phones and directly implement video Baidu cloud storage via WIFI. There is a vulnerability in the Foscamcamera Telnet feature, and the device has hidden Telnet functionality, which is not recorded anywhere. The Telnet feature makes it easier for an attacker to exploit other vulnerabilities or penetrate the intranet further.
| VAR-201706-1111 | No CVE | Foscam camera FTP Server Account Hard Coded Password Vulnerability |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
Foscamcamera is a webcam that can push messages to mobile phones and directly implement video Baidu cloud storage via WIFI. The FoscamcameraFTP server account has a hard-coded password vulnerability. The built-in FTP user password is hard-coded, so the default FTP user password is always empty and cannot be changed.
| VAR-201706-1121 | No CVE | Foscam camera web user interface hides hard-coded credentials vulnerabilities |
CVSS V2: 7.5 CVSS V3: - Severity: HIGH |
Foscamcamera is a webcam that can push messages to mobile phones and directly implement video Baidu cloud storage via WIFI. The FoscamcameraWeb user interface hides hard-coded credentials vulnerabilities. All Foscams have hidden and hard-coded credentials that are unaffected by user configuration. These credentials can access the web user interface of some devices. The actions that can be performed depend on the model of the device, such as Opticami5, which allows visitors to control the telnetd service and reset the device to factory settings.
| VAR-201706-1123 | No CVE | Foscam camera firewall configuration error vulnerability |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Foscamcamera is a webcam that can push messages to mobile phones and directly implement video Baidu cloud storage via WIFI. There is a configuration error in the Foscamcamera firewall. The Foscam camera device has a firewall function, but the firewall only restricts access to the web user interface (ports 80 and 443), and the IP address denied by the firewall can still access other services, such as ONVIF. (888 ports), FTP (50021 ports), RTSP (65534 ports), and telnet (23 ports). In the case that the request is rejected by the firewall, the firewall will return different results for the validity of the credential, the invalid credential will return an error-2 error, and the valid credential will return an error-8 error, so even if there is a firewall, the user can The voucher is violently enumerated.
| VAR-201706-1126 | No CVE | Foscam camera Web Account Default Credential Vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Foscamcamera is a webcam that can push messages to mobile phones and directly implement video Baidu cloud storage via WIFI. There is a default credential vulnerability in the FoscamcameraWeb account. The Foscam camera device can access the web user interface using the default credentials with the username admin and password blank. In addition to gaining access to the device, attackers can upload and download files via the built-in FTP server and watch live video from the camera via the RTSP protocol.
| VAR-201706-1120 | No CVE | Foscam camera remote command execution vulnerability |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Foscamcamera is a webcam that can push messages to mobile phones and directly implement video Baidu cloud storage via WIFI. Foscamcamera has a remote command injection vulnerability in the modelName in the /mnt/mtd/app/config/ProductConfig.xml file. By using the configuration recovery feature to install the ProductConfig.xml file into the device, an attacker can exploit the vulnerability to execute arbitrary commands.
| VAR-201706-1118 | No CVE | Foscam camera adds user remote command execution vulnerability |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
FOSCAM Group is a national high-tech enterprise specializing in the design, development, manufacture and sale of network cameras, network video recorders and other products. Foscamcamera adds a remote command execution vulnerability to the usrName parameter in the CGIProxy.fcgiaddAccount function at the user. Since the web page is run with root privileges, the command will also be executed with root privileges. However, the use of this vulnerability requires a valid certificate
| VAR-201706-1113 | No CVE | Foscam camera RtspServer Denial of Service Vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Foscamcamera is a webcam that can push messages to mobile phones and directly implement video Baidu cloud storage via WIFI. A denial of service vulnerability exists in FoscamcameraRtspServer that could allow an attacker to disconnect or freeze a video source. The Foscam camera device RTSP service incorrectly handles negative numbers when processing the \"Content-Length\" in the request, causing the RTSP service memory to overflow or crash, or a single request entering an infinite loop. Since the RTSP service has a daemon, when the service crashes, a new service process is restarted, so the attacker is more likely to boot the process into an infinite loop. This denial of service attack will disconnect the video or freeze the video, and the only way for the user to resume video playback is to reboot the device. This vulnerability only exists on some devices or part of the firmware version.
| VAR-201706-1115 | No CVE | Foscam camera SetDNS Buffer Overflow Vulnerability |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Foscamcamera is a webcam that can push messages to mobile phones and directly implement video Baidu cloud storage via WIFI. A buffer overflow vulnerability exists in FoscamcameraONVIFSetDNS. A buffer overflow can cause a service to crash or execute arbitrary code. An unauthenticated attacker can trigger a buffer overflow on the remote stack via the devicemgmtSetDNS method. This vulnerability only exists on some devices or part of the firmware version.
| VAR-201706-1129 | No CVE | Foscam camera lacks multiple login limit vulnerabilities |
CVSS V2: 2.6 CVSS V3: - Severity: LOW |
Foscamcamera is a webcam that can push messages to mobile phones and directly implement video Baidu cloud storage via WIFI. Foscamcamera lacks multiple login limit vulnerabilities. The Foscam camera device does not limit the number of error credentials provided by users, so an attacker can obtain valid credentials by violent enumeration.
| VAR-201706-1125 | No CVE | Foscam camera configuration backup file is hardcoded to protect the vulnerability |
CVSS V2: 7.5 CVSS V3: - Severity: HIGH |
Foscamcamera is a webcam that can push messages to mobile phones and directly implement video Baidu cloud storage via WIFI. The Foscamcamera configuration backup file is hard-coded and protected. The configuration file of the Foscam camera device contains the administrator's password, which can be exported from the device. Although the exported backup file is encrypted, the credentials used for decryption are also hard-coded. If the attacker has analyzed the device and got hard-coded credentials, the administrator's password can be obtained.