VARIoT IoT vulnerabilities database
| VAR-202606-1001 | CVE-2026-30652 | VIVOTEK Inc. of Network Camera FD8136 Classic buffer overflow vulnerability in firmware |
CVSS V2: - CVSS V3: 8.8 Severity: HIGH |
A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. This flaw allows an authenticated attacker to execute arbitrary code as root on the device. - All information handled by the software may be overwritten. - The software may completely shut down
| VAR-202606-1876 | CVE-2026-30650 | VIVOTEK Inc. of Network Camera FD8136 Classic buffer overflow vulnerability in firmware |
CVSS V2: - CVSS V3: 8.8 Severity: HIGH |
A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. This flaw allows an authenticated attacker to execute arbitrary code as root on the device remotely. root This allows execution based on the available permissions.- All information handled by the software may be leaked to external parties. - All information handled by the software may be overwritten. - The software may completely shut down
| VAR-202606-1525 | CVE-2026-30649 | VIVOTEK Inc. of Network Camera FD8136 Stack-based buffer overflow vulnerability in firmware |
CVSS V2: - CVSS V3: 7.3 Severity: HIGH |
Buffer Overflow vulnerability in VIVOTEK INC FD8136-VVTK-0300a allows a remote attacker to execute arbitrary code via the set_getparam.cgi component. - Some of the information handled by the software may be overwritten. - Some parts of the software may stop working
| VAR-202606-1877 | CVE-2026-35717 | VIVOTEK Inc. of Network Camera FD8136 Stack-based buffer overflow vulnerability in firmware |
CVSS V2: - CVSS V3: 6.3 Severity: MEDIUM |
A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via a crafted POST request to the /cgi-bin/admin/export_language.cgi endpoint. The handler passes the attacker-controlled Content-Length value directly to fread() as the read size into a fixed-size 0x60-byte stack buffer, overwriting the saved link register. The binary is compiled without stack canaries. The handler is controlled by the attacker. - Some of the information handled by the software may be overwritten. - Some parts of the software may stop working
| VAR-202605-1119 | CVE-2026-35194 | Apache Software Foundation of Apache Flink Code injection vulnerability in |
CVSS V2: - CVSS V3: 8.1 Severity: HIGH |
Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission privileges to execute arbitrary code on TaskManagers via maliciously crafted SQL queries. The vulnerability affects JSON functions (1.15.0+) and LIKE expressions with ESCAPE clauses (1.17.0+). User-controlled strings are interpolated into generated Java code without proper escaping, allowing attackers to break out of string literals and inject arbitrary expressions.
Users are recommended to upgrade to either version 1.20.4, 2.0.2, 2.1.2 or 2.2.1, which fixes this issue. 1.20.4 , 2.0.2 , 2.1.2 or 2.2.1 We recommend that you upgrade to .All information handled by the software may be leaked to the outside. All information handled by the software may be rewritten. Furthermore, the software will not stop. Furthermore, attacks that exploit this vulnerability will not affect other software
| VAR-202605-3704 | CVE-2026-20182 | Cisco Systems Cisco Catalyst SD-WAN Manager Vulnerabilities related to authentication in multiple products, such as |
CVSS V2: - CVSS V3: 10.0 Severity: CRITICAL |
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The section of this advisory includes Show Control Connections guidance to help with system checks.
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to the affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric. A successful attack would allow the attacker to gain administrator privileges. Cisco Catalyst SD-WAN Controller He has high authority within the company. root This will allow you to log in as a non-user account. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks exploiting this vulnerability may affect other software as well
| VAR-202605-2181 | CVE-2026-31156 | OpenPLC Project of OpenPLC_v3 Path traversal vulnerability in firmware |
CVSS V2: - CVSS V3: 6.5 Severity: MEDIUM |
A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program compiled from glue_generator.cpp does not perform any validation on the file path parameters passed via the command line. The user-controlled input parameters are directly passed to the underlying file operation functions (fopen/ifstream/ofstream) for file reading and writing. An attacker can exploit this vulnerability by constructing a malicious path to read arbitrary readable files. OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) This has a path injection vulnerability. In addition, information handled by the software will not be rewritten. Furthermore, the software will not stop. Furthermore, attacks exploiting this vulnerability will not affect other software
| VAR-202605-3727 | CVE-2026-26083 | fortinet's FortiSandbox Vulnerabilities related to lack of authentication in multiple products, such as |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, FortiSandbox PaaS 23.3 all versions, FortiSandbox PaaS 23.1 all versions, FortiSandbox PaaS 22.2 all versions, FortiSandbox PaaS 22.1 all versions, FortiSandbox PaaS 21.4 all versions, FortiSandbox PaaS 21.3 all versions, FortiSandbox PaaS 5.0.0 through 5.0.1, FortiSandbox PaaS 4.4.5 through 4.4.8 may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software
| VAR-202605-3769 | CVE-2026-36983 | D-Link Corporation of DCS-932L Firmware Command injection vulnerability in |
CVSS V2: - CVSS V3: 7.3 Severity: HIGH |
D-Link DCS-932L v2.18.01 is vulnerable to Command Injection in the function sub_42EF14 of the file /bin/alphapd. The manipulation of the argument LightSensorControl leads to command injection. LightSensorControl Command injection occurs through this operation.Some of the information handled by the software may be leaked to the outside. Also, some of the information handled by the software may be rewritten. Furthermore, some of the software may stop functioning. Furthermore, attacks that exploit this vulnerability will not affect other software
| VAR-202605-3781 | CVE-2026-8273 | D-Link Corporation of D-Link DNS-320 Multiple vulnerabilities in firmware |
CVSS V2: 5.8 CVSS V3: 4.7 Severity: Medium |
A weakness has been identified in D-Link DNS-320 2.06B01. This impacts the function cgi_set_host/cgi_set_ntp/cgi_fan_control/cgi_merge_user of the file /cgi-bin/system_mgr.cgi. This manipulation causes os command injection. It is possible to initiate the attack remotely. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software
| VAR-202605-3065 | CVE-2026-8272 | D-Link Corporation of D-Link DNS-320 Multiple vulnerabilities in firmware |
CVSS V2: 5.8 CVSS V3: 4.7 Severity: Low |
A security flaw has been discovered in D-Link DNS-320 2.06B01. This affects the function delete/rename/copy/move/chmod/chown of the file /cgi-bin/webfile_mgr.cgi. The manipulation results in os command injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. This vulnerability is: /cgi-bin/webfile_mgr.cgi File delete , rename , copy , move , chmod , chown This will affect the functionality. An exploit has been exposed and may be used to carry out attacks.All information handled by the software may be leaked to the outside. All information handled by the software may be rewritten. Furthermore, the software may stop working completely
| VAR-202605-2715 | CVE-2026-8271 | D-Link Corporation of D-Link DNS-320 Multiple vulnerabilities in firmware |
CVSS V2: 5.8 CVSS V3: 4.7 Severity: Low |
A vulnerability was identified in D-Link DNS-320 2.06B01. The impacted element is the function cgi_speed/cgi_dhcpd_lease/cgi_ddns/cgi_set_ip/cgi_upnp_del/cgi_dhcpd/cgi_upnp_add/cgi_upnp_edit of the file /cgi-bin/network_mgr.cgi. The manipulation leads to os command injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software
| VAR-202605-0817 | CVE-2026-8265 | Shenzhen Tenda Technology Co.,Ltd. of AC6 Multiple vulnerabilities in firmware |
CVSS V2: 5.8 CVSS V3: 4.7 Severity: Low |
A security vulnerability has been detected in Tenda AC6 15.03.06.23. Affected by this issue is the function get_log_file of the file /goform/getLogFile of the component httpd. The manipulation of the argument wans.flag leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software
| VAR-202605-1581 | CVE-2026-8264 | Shenzhen Tenda Technology Co.,Ltd. of AC6 Multiple vulnerabilities in firmware |
CVSS V2: 6.5 CVSS V3: 6.3 Severity: Low |
A weakness has been identified in Tenda AC6 15.03.06.23. Affected by this vulnerability is the function formWifiApScan of the file /goform/WifiApScan of the component httpd. Executing a manipulation of the argument wl2g.public.country/wl5g.public.country can lead to os command injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The exploit is publicly available and could be used to carry out attacks.All information handled by the software may be leaked to the outside. All information handled by the software may be rewritten. Furthermore, the software may stop working completely
| VAR-202605-1567 | CVE-2026-8260 | D-Link Corporation of DCS-935L Multiple vulnerabilities in firmware |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: High |
A vulnerability was found in D-Link DCS-935L up to 1.10.01. The impacted element is the function SetDeviceSettings of the file /web/cgi-bin/hnap/hnap_service of the component HNAP Service. The manipulation of the argument AdminPassword results in buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. D-Link DCS-935L version 1.10.01 The vulnerability was discovered in 2017. The exploit has been exposed and could be exploited.All information handled by the software may be leaked to the outside. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software
| VAR-202605-0316 | CVE-2026-8259 | Shenzhen Tenda Technology Co.,Ltd. of AC6 Multiple vulnerabilities in firmware |
CVSS V2: 5.8 CVSS V3: 4.7 Severity: Low |
A vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /goform/telnet of the component httpd. The manipulation of the argument lan.ip leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. This exploit is publicly available and may be exploited.All information handled by the software may be leaked to the outside. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software
| VAR-202604-2450 | CVE-2026-7470 | Shenzhen Tenda Technology Co.,Ltd. of 4g300 Multiple vulnerabilities in firmware |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: High |
A flaw has been found in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. Affected is the function sub_427C3C of the file /goform/SafeMacFilter. This manipulation of the argument page causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used. Because it allows for remote attacks and exploits have been publicly exposed, it is at risk of being exploited.All information handled by the software may be leaked to the outside. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software
| VAR-202604-3188 | CVE-2026-7469 | Shenzhen Tenda Technology Co.,Ltd. of 4g300 Multiple vulnerabilities in firmware |
CVSS V2: 6.5 CVSS V3: 6.3 Severity: Low |
A vulnerability was detected in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. This impacts the function sub_425A28 of the file /goform/DelFil. The manipulation of the argument delflag results in command injection. The attack may be launched remotely. The exploit is now public and may be used. The exploit has already been publicly disclosed and is at risk of being exploited.Some of the information handled by the software may be leaked to the outside. Also, some of the information handled by the software may be rewritten. Furthermore, some of the software may stop functioning. Furthermore, attacks that exploit this vulnerability will not affect other software
| VAR-202604-3710 | CVE-2026-32655 | Dell's Alienware Command Center Least privilege violation vulnerability in |
CVSS V2: - CVSS V3: 5.3 Severity: MEDIUM |
Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain a Least Privilege Violation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software
| VAR-202604-3463 | CVE-2026-31255 | Shenzhen Tenda Technology Co.,Ltd. of AC18 Command injection vulnerability in firmware |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
A command injection vulnerability exists in Tenda AC18 V15.03.05.05_multi. The vulnerability is located in the /goform/SetSambaCfg interface, where improper handling of the guestuser parameter allows attackers to execute arbitrary system commands. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software