VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202401-2495 CVE-2023-51965 CVSS V2: -
CVSS V3: 9.8
Severity: CRITICAL
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function setIptvInfo.
VAR-202401-2371 CVE-2023-51964 CVSS V2: -
CVSS V3: 9.8
Severity: CRITICAL
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function setIptvInfo.
VAR-202401-2419 CVE-2023-51963 CVSS V2: -
CVSS V3: 9.8
Severity: CRITICAL
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function setIptvInfo.
VAR-202401-0723 CVE-2023-51960 Tenda AX1803 buffer overflow vulnerability (CNVD-2024-02210) CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formGetIptv. Tenda AX1803 is a dual-band Gigabit WIFI6 router from China's Tenda Company. This vulnerability is caused by the iptv.city.vlan parameter of the formGetIptv method failing to correctly verify the length of the input data. An attacker can use this vulnerability to execute arbitrary code on the system or Lead to denial of service attacks
VAR-202401-0357 CVE-2023-51959 Tenda AX1803 buffer overflow vulnerability (CNVD-2024-02209) CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formGetIptv. Tenda AX1803 is a dual-band Gigabit WIFI6 router from China's Tenda Company. This vulnerability is caused by the adv.iptv.stbpvid parameter of the formGetIptv method failing to correctly verify the length of the input data. An attacker can use this vulnerability to execute arbitrary code on the system or Lead to denial of service attacks
VAR-202401-0722 CVE-2023-51958 Tenda AX1803 buffer overflow vulnerability (CNVD-2024-02212) CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv. Tenda AX1803 is a dual-band Gigabit WIFI6 router from China's Tenda Company. This vulnerability is caused by the iptv.stb.port parameter of the formGetIptv method failing to correctly verify the length of the input data. An attacker can use this vulnerability to execute arbitrary code on the system or Lead to denial of service attacks
VAR-202401-0658 CVE-2023-51957 Tenda AX1803 buffer overflow vulnerability (CNVD-2024-02211) CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formGetIptv. Tenda AX1803 is a dual-band Gigabit WIFI6 router from China's Tenda Company. This vulnerability is caused by the iptv.stb.mode parameter of the formGetIptv method failing to correctly verify the length of the input data. An attacker can use this vulnerability to execute arbitrary code on the system or Lead to denial of service attacks
VAR-202401-0720 CVE-2023-51956 Tenda AX1803 buffer overflow vulnerability (CNVD-2024-02215) CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formSetIptv. Tenda AX1803 is a dual-band Gigabit WIFI6 router from China's Tenda Company. This vulnerability is caused by the iptv.city.vlan parameter of the formSetIptv method failing to correctly verify the length of the input data. An attacker can use this vulnerability to execute arbitrary code on the system or Lead to denial of service attacks
VAR-202401-0796 CVE-2023-51955 Tenda AX1803 buffer overflow vulnerability (CNVD-2024-02213) CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv. Tenda AX1803 is a dual-band Gigabit WIFI6 router from China's Tenda Company. This vulnerability is caused by the adv.iptv.stballvlans parameter of the formSetIptv method failing to correctly verify the length of the input data. An attacker can use this vulnerability to execute arbitrary code on the system or Lead to denial of service attacks
VAR-202401-0265 CVE-2023-51954 Tenda AX1803 buffer overflow vulnerability CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formSetIptv. Tenda AX1803 is a dual-band Gigabit WIFI6 router from China's Tenda Company. This vulnerability is caused by the iptv.stb.port parameter of the formSetIptv method failing to correctly verify the length of the input data. A remote attacker can use this vulnerability to execute arbitrary code on the system or cause a denial of service attack
VAR-202401-0719 CVE-2023-51953 Tenda AX1803 buffer overflow vulnerability (CNVD-2024-02217) CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv. Tenda AX1803 is a dual-band Gigabit WIFI6 router from China's Tenda Company. An attacker can exploit this vulnerability to execute arbitrary code on the system by sending a specially crafted HTTP request using the iptv.stb.mode parameter
VAR-202401-0657 CVE-2023-51952 Tenda AX1803 buffer overflow vulnerability (CNVD-2024-02214) CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv. Tenda AX1803 is a dual-band Gigabit WIFI6 router from China's Tenda Company. This vulnerability is caused by the adv.iptv.stbpvid parameter of the formSetIptv method failing to correctly verify the length of the input data. An attacker can use this vulnerability to execute arbitrary code on the system or Lead to denial of service attacks
VAR-202401-2418 CVE-2023-51966 CVSS V2: -
CVSS V3: 9.8
Severity: CRITICAL
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function setIptvInfo.
VAR-202401-0659 CVE-2023-51961 Tenda AX1803 buffer overflow vulnerability (CNVD-2024-02208) CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv. Tenda AX1803 is a dual-band Gigabit WIFI6 router from China's Tenda Company. This vulnerability is caused by the adv.iptv.stballvlans parameter of the formGetIptv method failing to correctly verify the length of the input data. An attacker can use this vulnerability to execute arbitrary code on the system or Lead to denial of service attacks
VAR-202401-1164 CVE-2023-51972 Tenda AX1803 command injection vulnerability CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
Tenda AX1803 v1.0.0.1 was discovered to contain a command injection vulnerability via the function fromAdvSetLanIp. Tenda AX1803 is a dual-band Gigabit WIFI6 router from China's Tenda Company. The vulnerability is caused by the fromAdvSetLanIp method failing to correctly filter special characters, commands, etc. in the constructed command. An attacker could exploit this vulnerability to cause arbitrary command execution
VAR-202401-1714 CVE-2023-51971 Tenda AX1803 adv.iptv.stbpvid parameter buffer overflow vulnerability in getIptvInfo method CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function getIptvInfo. Tenda AX1803 is a dual-band Gigabit WIFI6 router from China's Tenda Company. This vulnerability is caused by the adv.iptv.stbpvid parameter of the getIptvInfo method failing to correctly verify the length of the input data. A remote attacker can use this vulnerability to execute arbitrary code on the system. or result in a denial of service attack
VAR-202401-1073 CVE-2023-49427 Tenda AX12 buffer overflow vulnerability CVSS V2: 7.8
CVSS V3: 7.5
Severity: HIGH
Buffer Overflow vulnerability in Tenda AX12 V22.03.01.46, allows remote attackers to cause a denial of service (DoS) via list parameter in SetNetControlList function. Tenda AX12 is a dual-band Gigabit Wifi 6 wireless router from China's Tenda Company. Tenda AX12 V22.03.01.46 version has a buffer overflow vulnerability. The vulnerability results from a bounds error when the application handles untrusted input
VAR-202401-0859 CVE-2023-41603 D-Link R15 code issue vulnerability CVSS V2: 5.0
CVSS V3: 5.3
Severity: MEDIUM
D-Link R15 before v1.08.02 was discovered to contain no firewall restrictions for IPv6 traffic. This allows attackers to arbitrarily access any services running on the device that may be inadvertently listening via IPv6. D-Link R15 is a wireless router made by China D-Link Company. D-Link R15 v1.08.02 has a code issue vulnerability
VAR-202401-2395 CVE-2022-46025 TOTOLINK N200RE Access Control Error Vulnerability CVSS V2: 9.4
CVSS V3: 9.1
Severity: CRITICAL
Totolink N200RE_V5 V9.3.5u.6255_B20211224 is vulnerable to Incorrect Access Control. The device allows remote attackers to obtain Wi-Fi system information, such as Wi-Fi SSID and Wi-Fi password, without logging into the management page. TOTOLINK N200RE is a wireless broadband router that uses 11N wireless technology
VAR-202401-0630 CVE-2023-7223 TOTOLINK T6 access control error vulnerability CVSS V2: 5.0
CVSS V3: 5.3
Severity: MEDIUM
A vulnerability classified as problematic has been found in Totolink T6 4.1.9cu.5241_B20210923. This affects an unknown part of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument topicurl with the input showSyslog leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249867. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. TOTOLINK T6 is a wireless dual-band router made by China Zeon Electronics (TOTOLINK) Company. TOTOLINK T6 version 4.1.9cu.5241_B20210923 has an access control error vulnerability. The vulnerability is caused by an access control error in the file /cgi-bin/cstecgi.cgi. An attacker could exploit this vulnerability to obtain sensitive information