VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-201701-0164 CVE-2016-10177 D-Link DWR-932B Administrator with a specific password on the router and root Login vulnerability

Related entries in the VARIoT exploits database: VAR-E-201701-0681
CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
An issue was discovered on the D-Link DWR-932B router. Undocumented TELNET and SSH services provide logins to admin with the password admin and root with the password 1234. D-LinkDWR-932Brouter is a wireless router product from D-Link. A security hole exists in the D-Link DWR-932B router using firmware version 02.02eu. An attacker could exploit the vulnerability to bypass security restrictions and perform unauthorized operations. Dlink DWR-932B is prone to the following security vulnerabilities: 1. An insecure default-password vulnerability 2. An authentication-bypass vulnerability 3. A security-bypass vulnerability 4. Multiple security weaknesses 5. An information-disclosure vulnerability 6. A command-injection vulnerability 7. This may lead to further attacks
VAR-201701-0165 CVE-2016-10178 D-Link DWR-932B In the router "/sbin/telnetd -l /bin/sh" Command launch vulnerability

Related entries in the VARIoT exploits database: VAR-E-201701-0681
CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
An issue was discovered on the D-Link DWR-932B router. HELODBG on port 39889 (UDP) launches the "/sbin/telnetd -l /bin/sh" command. D-LinkDWR-932B has an input validation vulnerability that allows remote attackers to exploit a vulnerability to submit a special request and execute the \"/sbin/telnetd-l/bin/sh\" command. Dlink DWR-932B is prone to the following security vulnerabilities: 1. An insecure default-password vulnerability 2. An authentication-bypass vulnerability 3. A security-bypass vulnerability 4. Multiple security weaknesses 5. An information-disclosure vulnerability 6. A command-injection vulnerability 7. Multiple directory-traversal vulnerabilities An attacker can exploit these issues to bypass certain security restrictions to perform unauthorized actions, bypass-authentication mechanism, gain access to potentially sensitive information, or execute arbitrary commands in the context of the affected device. This may lead to further attacks. A security vulnerability exists in D-Link DWR-932B routers using firmware version 02.02eu. An attacker could exploit this vulnerability to gain privileges
VAR-201701-0167 CVE-2016-10180 D-Link DWR-932B  Seed value in router  srand(time(0))  based on  WPS PIN  Vulnerabilities generated

Related entries in the VARIoT exploits database: VAR-E-201701-0681
CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
An issue was discovered on the D-Link DWR-932B router. WPS PIN generation is based on srand(time(0)) seeding. D-LinkDWR-932Brouter is a wireless router product from D-Link. A security vulnerability exists in the D-Link DWR-932B router using firmware version 02.02eu. An attacker could exploit the vulnerability to bypass security restrictions. Dlink DWR-932B is prone to the following security vulnerabilities: 1. An insecure default-password vulnerability 2. An authentication-bypass vulnerability 3. A security-bypass vulnerability 4. Multiple security weaknesses 5. An information-disclosure vulnerability 6. A command-injection vulnerability 7. Multiple directory-traversal vulnerabilities An attacker can exploit these issues to bypass certain security restrictions to perform unauthorized actions, bypass-authentication mechanism, gain access to potentially sensitive information, or execute arbitrary commands in the context of the affected device. This may lead to further attacks
VAR-201701-0168 CVE-2016-10181 D-Link DWR-932B Router Information Disclosure Vulnerability

Related entries in the VARIoT exploits database: VAR-E-201701-0681
CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
An issue was discovered on the D-Link DWR-932B router. qmiweb provides sensitive information for CfgType=get_homeCfg requests. D-LinkDWR-932Brouter is a wireless router product from D-Link. Dlink DWR-932B is prone to the following security vulnerabilities: 1. An insecure default-password vulnerability 2. An authentication-bypass vulnerability 3. A security-bypass vulnerability 4. Multiple security weaknesses 5. An information-disclosure vulnerability 6. A command-injection vulnerability 7. Multiple directory-traversal vulnerabilities An attacker can exploit these issues to bypass certain security restrictions to perform unauthorized actions, bypass-authentication mechanism, gain access to potentially sensitive information, or execute arbitrary commands in the context of the affected device. This may lead to further attacks
VAR-201701-0169 CVE-2016-10182 D-Link DWR-932B Router qmiweb Command injection vulnerability

Related entries in the VARIoT exploits database: VAR-E-201701-0681
CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
An issue was discovered on the D-Link DWR-932B router. qmiweb allows command injection with ` characters. D-LinkDWR-932B has an input validation vulnerability that allows remote attackers to exploit a vulnerability to submit a special request and execute arbitrary commands. Dlink DWR-932B is prone to the following security vulnerabilities: 1. An insecure default-password vulnerability 2. An authentication-bypass vulnerability 3. A security-bypass vulnerability 4. Multiple security weaknesses 5. An information-disclosure vulnerability 6. A command-injection vulnerability 7. Multiple directory-traversal vulnerabilities An attacker can exploit these issues to bypass certain security restrictions to perform unauthorized actions, bypass-authentication mechanism, gain access to potentially sensitive information, or execute arbitrary commands in the context of the affected device. This may lead to further attacks
VAR-201701-0170 CVE-2016-10183 D-Link DWR-932B Router qmiweb In ../ Vulnerability in traversal directory listing

Related entries in the VARIoT exploits database: VAR-E-201701-0681
CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
An issue was discovered on the D-Link DWR-932B router. qmiweb allows directory listing with ../ traversal. D-LinkDWR-932B has a directory traversal vulnerability that allows remote attackers to exploit a vulnerability to submit a special request to read arbitrary file content. Dlink DWR-932B is prone to the following security vulnerabilities: 1. An insecure default-password vulnerability 2. An authentication-bypass vulnerability 3. A security-bypass vulnerability 4. Multiple security weaknesses 5. An information-disclosure vulnerability 6. A command-injection vulnerability 7. Multiple directory-traversal vulnerabilities An attacker can exploit these issues to bypass certain security restrictions to perform unauthorized actions, bypass-authentication mechanism, gain access to potentially sensitive information, or execute arbitrary commands in the context of the affected device. This may lead to further attacks
VAR-201701-0172 CVE-2016-10185 D-Link DWR-932B In the router /var/miniupnpd.conf In secure_mode=no Vulnerability where the row exists

Related entries in the VARIoT exploits database: VAR-E-201701-0681
CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
An issue was discovered on the D-Link DWR-932B router. A secure_mode=no line exists in /var/miniupnpd.conf. D-Link DWR-932B The router has /var/miniupnpd.conf In secure_mode=no There are vulnerabilities that contain rows.It may be affected unspecified. A security vulnerability exists in the D-LinkDWR-932B/var/miniupnpd.conf device that allows remote attackers to exploit vulnerabilities to bypass security restrictions and perform unauthorized operations. Dlink DWR-932B is prone to the following security vulnerabilities: 1. An insecure default-password vulnerability 2. An authentication-bypass vulnerability 3. A security-bypass vulnerability 4. Multiple security weaknesses 5. An information-disclosure vulnerability 6. A command-injection vulnerability 7. This may lead to further attacks. A security vulnerability exists in D-Link DWR-932B routers using firmware version 02.02eu
VAR-201701-0173 CVE-2016-10186 D-Link DWR-932B In the router /var/miniupnpd.conf In no deny Vulnerabilities with rules

Related entries in the VARIoT exploits database: VAR-E-201701-0681
CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
An issue was discovered on the D-Link DWR-932B router. /var/miniupnpd.conf has no deny rules. D-Link DWR-932B The router has /var/miniupnpd.conf In no deny A vulnerability exists that contains rules.It may be affected unspecified. A security vulnerability exists in the D-LinkDWR-932B/var/miniupnpd.conf device that allows remote attackers to exploit vulnerabilities to bypass security restrictions and perform unauthorized operations. Dlink DWR-932B is prone to the following security vulnerabilities: 1. An insecure default-password vulnerability 2. An authentication-bypass vulnerability 3. A security-bypass vulnerability 4. Multiple security weaknesses 5. An information-disclosure vulnerability 6. A command-injection vulnerability 7. This may lead to further attacks. An attacker could exploit this vulnerability to affect the integrity, confidentiality, and availability of data
VAR-201701-0755 CVE-2017-5632 ASUS RT-N56U Wireless Router Vulnerabilities in firmware CVSS V2: 3.3
CVSS V3: 6.5
Severity: MEDIUM
An issue was discovered on the ASUS RT-N56U Wireless Router with Firmware 3.0.0.4.374_979. When executing an "nmap -O" command that specifies an IP address of an affected device, one can crash the device's WAN connection, causing disconnection from the Internet, a Denial of Service (DoS). The attack is only possible from within the local area network. A security vulnerability exists in ASUSRT-N56UWirelessRouter using firmware version 3.0.0.4.374_979. An attacker could exploit the vulnerability to cause the device's WAN connection to crash, the network to fail to connect, and a denial of service. ASUS RT-N56U is prone to an unspecified denial-of-service vulnerability
VAR-201701-0171 CVE-2016-10184 D-Link DWR-932B Router qmiweb In .. % 2f Vulnerability in reading files in traversal

Related entries in the VARIoT exploits database: VAR-E-201701-0681
CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
An issue was discovered on the D-Link DWR-932B router. qmiweb allows file reading with ..%2f traversal. D-Link DWR-932B Router qmiweb In .. D-LinkDWR-932B handles a security vulnerability in %2f that allows remote attackers to exploit a vulnerability to submit a special request to read arbitrary file content. Dlink DWR-932B is prone to the following security vulnerabilities: 1. An insecure default-password vulnerability 2. An authentication-bypass vulnerability 3. A security-bypass vulnerability 4. Multiple security weaknesses 5. An information-disclosure vulnerability 6. A command-injection vulnerability 7. Multiple directory-traversal vulnerabilities An attacker can exploit these issues to bypass certain security restrictions to perform unauthorized actions, bypass-authentication mechanism, gain access to potentially sensitive information, or execute arbitrary commands in the context of the affected device. This may lead to further attacks. D-Link DWR-932B routers with firmware version 02.02eu have a path traversal vulnerability
VAR-201701-0166 CVE-2016-10179 D-Link DWR-932B Hardcoded in router WPS PIN Vulnerability using

Related entries in the VARIoT exploits database: VAR-E-201701-0681
CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
An issue was discovered on the D-Link DWR-932B router. There is a hardcoded WPS PIN of 28296607. D-LinkDWR-932Brouter is a wireless router product from D-Link. A security hole exists in the D-Link DWR-932B router using firmware version 02.02eu. An attacker could exploit the vulnerability to bypass authentication and perform unauthorized operations. Dlink DWR-932B is prone to the following security vulnerabilities: 1. An insecure default-password vulnerability 2. An authentication-bypass vulnerability 3. A security-bypass vulnerability 4. Multiple security weaknesses 5. An information-disclosure vulnerability 6. A command-injection vulnerability 7. Multiple directory-traversal vulnerabilities An attacker can exploit these issues to bypass certain security restrictions to perform unauthorized actions, bypass-authentication mechanism, gain access to potentially sensitive information, or execute arbitrary commands in the context of the affected device. This may lead to further attacks
VAR-201701-1169 No CVE Design loopholes in the micro-farming remote control smart lock system CVSS V2: 4.7
CVSS V3: -
Severity: MEDIUM
Micro-farming remote control smart lock system is a kind of smart card identification (including proximity card, IC card, TM card, etc.). The micro-farming remote lock smart lock system has a design loophole when used in conjunction with the micro-farming WG2082 mobile phone APP door lock controller, which can be remotely replayed and the lock can be arbitrarily opened or closed.
VAR-201702-1034 CVE-2016-9684 Dell SonicWALL Secure Remote Access Server Web Remote Command Injection Vulnerability in Management Interface CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the 'viewcert' CGI (/cgi-bin/viewcert) component responsible for processing SSL certificate information. The CGI application doesn't properly escape the information it's passed in the 'CERT' variable before a call to system() is performed - allowing for remote command injection. Exploitation of this vulnerability yields shell access to the remote machine under the nobody user account. DellSonicWallSecureRemoteAccess is a SonicWALL Secure Remote Access Series appliance in the DellSonicWall Secure Mobile Access Solution. Dell SonicWall Secure Remote Access is prone to multiple command-injection vulnerabilities because it fails to properly sanitize user-supplied input. Exploiting these issues could allow an attacker to execute arbitrary commands in context of the affected application. Failed exploit attempts will result in a denial-of-service condition
VAR-201702-1032 CVE-2016-9682 Dell SonicWall Secure Remote Access Server Command Injection Vulnerability CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrative interface. These vulnerabilities occur in the diagnostics CGI (/cgi-bin/diagnostics) component responsible for emailing out information about the state of the system. The application doesn't properly escape the information passed in the 'tsrDeleteRestartedFile' or 'currentTSREmailTo' variables before making a call to system(), allowing for remote command injection. Exploitation of this vulnerability yields shell access to the remote machine under the nobody user account. DellSonicWallSecureRemoteAccess is a SonicWALL Secure Remote Access Series appliance in the DellSonicWall Secure Mobile Access Solution. Exploiting these issues could allow an attacker to execute arbitrary commands in context of the affected application. Failed exploit attempts will result in a denial-of-service condition
VAR-201702-1033 CVE-2016-9683 Dell SonicWALL Secure Remote Access Server Web Remote command injection vulnerability in management interface CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the 'extensionsettings' CGI (/cgi-bin/extensionsettings) component responsible for handling some of the server's internal configurations. The CGI application doesn't properly escape the information it's passed when processing a particular multi-part form request involving scripts. The filename of the 'scriptname' variable is read in unsanitized before a call to system() is performed - allowing for remote command injection. Exploitation of this vulnerability yields shell access to the remote machine under the nobody user account. This is SonicWall Issue ID 181195. DellSonicWallSecureRemoteAccess is a SonicWALL Secure Remote Access Series appliance in the DellSonicWall Secure Mobile Access Solution. Exploiting these issues could allow an attacker to execute arbitrary commands in context of the affected application. Failed exploit attempts will result in a denial-of-service condition
VAR-201703-0201 CVE-2016-8232 plural Lenovo IBM BladeCenter of AMM In DOM -Based cross-site scripting vulnerability CVSS V2: 4.3
CVSS V3: 6.1
Severity: MEDIUM
Document Object Model-(DOM) based cross-site scripting vulnerability in the Advanced Management Module (AMM) versions earlier than 66Z of Lenovo IBM BladeCenter HS22, HS22V, HS23, HS23E, HX5 allows an unauthenticated attacker with access to the AMM's IP address to send a crafted URL that could inject a malicious script to access a user's AMM data such as cookies or other session information. IBM BladeCenter Advanced Management Module is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks. IBM BladeCenter Advanced Management Module running firmware versions prior to 3.66z are vulnerable. IBM BladeCenter Systems is a high-performance blade server system developed by IBM Corporation in the United States
VAR-201701-0864 CVE-2016-9249 BIG-IP Virtual server Traffic Management Microkernel Restarted vulnerabilities CVSS V2: 7.8
CVSS V3: 7.5
Severity: HIGH
An undisclosed traffic pattern received by a BIG-IP Virtual Server with TCP Fast Open enabled may cause the Traffic Management Microkernel (TMM) to restart, resulting in a Denial-of-Service (DoS). Multiple F5 BIG-IP products are prone to a denial-of-service vulnerability. An attacker can exploit this issue to cause a a denial-of-service condition. F5 BIG-IP Analytics and others are products of F5 Corporation of the United States. F5 BIG-IP Analytics is a suite of web application performance analysis software. APM is a set of solutions that provide secure and unified access to business-critical applications and networks. LTM is a local traffic manager. The following products and versions are affected: F5 BIG-IP LTM version 12.0.0 to 12.1.1; BIG-IP AAM version 12.0.0 to 12.1.1; BIG-IP AFM version 12.0.0 to 12.1.1; BIG-IP Analytics version 12.0.0 through 12.1.1; BIG-IP APM version 12.0.0 through 12.1.1; BIG-IP ASM version 12.0.0 through 12.1.1; BIG-IP DNS version 12.0.0 to version 12.1.1; BIG-IP Link Controller version 12.0.0 to version 12.1.1; BIG-IP PEM version 12.0.0 to version 12.1.1; BIG-IP WebSafe version 12.0.0 to version 12.1.1
VAR-201701-1167 No CVE Schneider M218 TCP / IP Stack Denial of Service Vulnerability CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
Modicon M218 is a compact programmable logic controller produced by Schneider Electric of France. Schneider Electric M218 TCP / IP protocol stack has a denial of service vulnerability. Due to sending an abnormal IP packet with an IP header to the M218 (IP_Total_Length field is 0 and IP_Protocol field is 6), the M218 protocol stack may crash and lose its response. Restart the power before returning to normal.
VAR-201701-0354 CVE-2016-8225 Lenovo Edge and Lenovo Slim USB keyboard Driver vulnerable to code execution with elevated privileges CVSS V2: 4.6
CVSS V3: 7.8
Severity: HIGH
Unquoted service path vulnerability in Lenovo Edge and Lenovo Slim USB Keyboard Driver versions earlier than 1.21 allows local users to execute code with elevated privileges. Lenovo63 and so on are all computers of China Lenovo. The LenovoEdgeUSBKeyboardDriver (aka LenovoSlimUSBKeyboard or LenovoLowProfileKeyboard) is one of the keyboard input drivers. The following products are affected: Lenovo Edge Keyboard Driver 1.20 and prior. Lenovo Slim USB Keyboard Driver 1.20 and prior
VAR-201702-0681 CVE-2017-5163 Belden Hirschmann GECKO Lite Managed Switch Information Disclosure Vulnerability CVSS V2: 4.3
CVSS V3: 5.9
Severity: MEDIUM
An issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. After an administrator downloads a configuration file, a copy of the configuration file, which includes hashes of user passwords, is saved to a location that is accessible without authentication by path traversal. BeldenHirschmannGECKOLiteManagedSwitch is a switch product from Belden Corporation of the United States. An information disclosure vulnerability exists in BeldenHirschmannGECKOLiteManagedSwitch 2.0.00 and earlier. An attacker could exploit this vulnerability to obtain sensitive information. This may result in further attacks