VARIoT IoT vulnerabilities database
| VAR-202309-0336 | CVE-2023-41202 | D-Link Systems, Inc. of DAP-1325 Out-of-bounds write vulnerability in firmware |
CVSS V2: 8.3 CVSS V3: 8.8 Severity: HIGH |
D-Link DAP-1325 SetAPLanSettings Mode Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1325 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of XML data provided to the HNAP1 SOAP endpoint. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-18828. D-Link Systems, Inc. of DAP-1325 An out-of-bounds write vulnerability exists in firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The D-Link DAP-1325 is a wireless access point/bridge manufactured by D-Link, primarily used to extend wireless network coverage and support the conversion between wired and wireless networks or the connection of different wireless networks
| VAR-202309-0329 | CVE-2023-41192 | D-Link Systems, Inc. of DAP-1325 in the firmware OS Command injection vulnerability |
CVSS V2: 8.3 CVSS V3: 8.8 Severity: HIGH |
D-Link DAP-1325 HNAP SetAPLanSettings PrimaryDNS Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1325 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of a request parameter provided to the HNAP1 SOAP endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-18812. D-Link Systems, Inc. of DAP-1325 The firmware has OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DAP-1325 is a wireless access point/bridge from D-Link, a Chinese company. It is mainly used to provide wireless network coverage and has a bridging function, which can convert a wired network into a wireless network or connect two wireless networks
| VAR-202309-0378 | CVE-2023-41201 | D-Link Systems, Inc. of DAP-1325 in the firmware OS Command injection vulnerability |
CVSS V2: 8.3 CVSS V3: 8.8 Severity: HIGH |
D-Link DAP-1325 HNAP SetSetupWizardStatus Enabled Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1325 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of a request parameter provided to the HNAP1 SOAP endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-18821. D-Link Systems, Inc. of DAP-1325 The firmware has OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DAP-1325 is a wireless access point/bridge from D-Link, a Chinese company. It is mainly used to provide wireless network coverage and has a bridging function. It can convert a wired network into a wireless network or connect two wireless networks
| VAR-202309-0302 | CVE-2023-41197 | D-Link Systems, Inc. of DAP-1325 in the firmware OS Command injection vulnerability |
CVSS V2: 8.3 CVSS V3: 8.8 Severity: HIGH |
D-Link DAP-1325 HNAP SetHostIPv6StaticSettings StaticDefaultGateway Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1325 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of a request parameter provided to the HNAP1 SOAP endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-18817. D-Link Systems, Inc. of DAP-1325 The firmware has OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The D-Link DAP-1325 is a wireless network extender manufactured by D-Link, primarily used to extend wireless network coverage and support wired/wireless network switching or connection to different wireless networks
| VAR-202309-0359 | CVE-2023-41219 | D-Link Systems, Inc. of DIR-3040 Out-of-bounds write vulnerability in firmware |
CVSS V2: - CVSS V3: 6.8 Severity: MEDIUM |
D-Link DIR-3040 prog.cgi SetWanSettings Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-3040 routers. Authentication is required to exploit this vulnerability.
The specific flaw exists within the prog.cgi binary, which handles HNAP requests made to the lighttpd webserver listening on TCP ports 80 and 443. The issue results from the lack of proper validation of a user-supplied string before copying it to a fixed-size stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-21619. D-Link Systems, Inc. of DIR-3040 An out-of-bounds write vulnerability exists in firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202309-0323 | CVE-2023-41189 | D-Link Systems, Inc. of DAP-1325 in the firmware OS Command injection vulnerability |
CVSS V2: 8.3 CVSS V3: 8.8 Severity: HIGH |
D-Link DAP-1325 HNAP SetAPLanSettings Gateway Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1325 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of a request parameter provided to the HNAP1 SOAP endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-18809. D-Link Systems, Inc. of DAP-1325 The firmware has OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DAP-1325 is a wireless access point/bridge from D-Link, a Chinese company. It is mainly used to provide wireless network coverage and has a bridging function, which can convert a wired network into a wireless network or connect two wireless networks
| VAR-202309-0477 | CVE-2023-39236 | ASUS RT-AC86U command injection vulnerability (CNVD-2023-70091) |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
ASUS RT-AC86U Traffic Analyzer - Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services. RT-AC86U is a router launched by ASUS with a wireless speed of 2900M, an external antenna, and a WAN access port with a Gigabit network port. RT-AC86U integrates ASUS AiProtection, which is equipped with the enterprise-level network security system of Trend Micro smart home network. AiProtection will provide protection even if the connected device itself does not have anti-virus function.
ASUS RT-AC86U has a command injection vulnerability in version 3.0.0.4.386.51529
| VAR-202309-0315 | CVE-2023-41200 | D-Link Systems, Inc. of DAP-1325 in the firmware OS Command injection vulnerability |
CVSS V2: 8.3 CVSS V3: 8.8 Severity: HIGH |
D-Link DAP-1325 HNAP SetHostIPv6StaticSettings StaticPrefixLength Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1325 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of a request parameter provided to the HNAP1 SOAP endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-18820. D-Link Systems, Inc. of DAP-1325 The firmware has OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DAP-1325 is a wireless access point/bridge from D-Link, a Chinese company. It is mainly used to provide wireless network coverage and has a bridging function, which can convert a wired network into a wireless network or connect two wireless networks
| VAR-202309-0326 | CVE-2023-41229 | D-Link Systems, Inc. of DIR-3040 Out-of-bounds write vulnerability in firmware |
CVSS V2: - CVSS V3: 8.8 Severity: HIGH |
D-Link DIR-3040 HTTP Request Processing Referer Heap-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-3040 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the prog.cgi binary, which handles HNAP requests made to the lighttpd webserver listening on TCP ports 80 and 443. The issue results from the lack of proper validation of a user-supplied string before copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-21671. D-Link Systems, Inc. of DIR-3040 An out-of-bounds write vulnerability exists in firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202309-0322 | CVE-2023-41198 | D-Link Systems, Inc. of DAP-1325 in the firmware OS Command injection vulnerability |
CVSS V2: 8.3 CVSS V3: 8.8 Severity: HIGH |
D-Link DAP-1325 HNAP SetHostIPv6StaticSettings StaticDNS1 Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1325 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of a request parameter provided to the HNAP1 SOAP endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-18818. D-Link Systems, Inc. of DAP-1325 The firmware has OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DAP-1325 is a wireless access point/bridge from D-Link, a Chinese company. It is mainly used to provide wireless network coverage and has a bridging function. It can convert a wired network into a wireless network or connect two wireless networks
| VAR-202309-0327 | CVE-2023-41220 | D-Link Systems, Inc. of DIR-3040 Out-of-bounds write vulnerability in firmware |
CVSS V2: - CVSS V3: 6.8 Severity: MEDIUM |
D-Link DIR-3040 prog.cgi SetSysEmailSettings Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-3040 routers. Authentication is required to exploit this vulnerability.
The specific flaw exists within the prog.cgi binary, which handles HNAP requests made to the lighttpd webserver listening on TCP ports 80 and 443. The issue results from the lack of proper validation of a user-supplied string before copying it to a fixed-size stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-21620. D-Link Systems, Inc. of DIR-3040 An out-of-bounds write vulnerability exists in firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202309-0293 | CVE-2023-41223 | D-Link Systems, Inc. of DIR-3040 Out-of-bounds write vulnerability in firmware |
CVSS V2: - CVSS V3: 6.8 Severity: MEDIUM |
D-Link DIR-3040 prog.cgi SetQuickVPNSettings PSK Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-3040 routers. Authentication is required to exploit this vulnerability.
The specific flaw exists within the prog.cgi binary, which handles HNAP requests made to the lighttpd webserver listening on TCP ports 80 and 443. The issue results from the lack of proper validation of a user-supplied string before copying it to a fixed-size stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-21623. D-Link Systems, Inc. of DIR-3040 An out-of-bounds write vulnerability exists in firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202309-0276 | CVE-2023-40357 | plural TP-LINK Technologies In the product OS Command injection vulnerability |
CVSS V2: 7.7 CVSS V3: 8.0 Severity: HIGH |
Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: Archer AX50 firmware versions prior to 'Archer AX50(JP)_V1_230529', Archer A10 firmware versions prior to 'Archer A10(JP)_V2_230504', Archer AX10 firmware versions prior to 'Archer AX10(JP)_V1.2_230508', and Archer AX11000 firmware versions prior to 'Archer AX11000(JP)_V1_230523'. TP-LINK Technologies The product has OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. TP-LINK Archer is a series of routers from China TP-LINK Company. This vulnerability is caused by the application's failure to properly filter special characters, commands, etc. that construct commands
| VAR-202309-0277 | CVE-2023-38563 | TP-LINK Technologies of Archer C1200 firmware and Archer C9 in the firmware OS Command injection vulnerability |
CVSS V2: - CVSS V3: 8.8 Severity: HIGH |
Archer C1200 firmware versions prior to 'Archer C1200(JP)_V2_230508' and Archer C9 firmware versions prior to 'Archer C9(JP)_V3_230508' allow a network-adjacent unauthenticated attacker to execute arbitrary OS commands. (DoS) It may be in a state
| VAR-202309-0275 | CVE-2023-36489 | plural TP-LINK Technologies In the product OS Command injection vulnerability |
CVSS V2: - CVSS V3: 8.8 Severity: HIGH |
Multiple TP-LINK products allow a network-adjacent unauthenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: TL-WR802N firmware versions prior to 'TL-WR802N(JP)_V4_221008', TL-WR841N firmware versions prior to 'TL-WR841N(JP)_V14_230506', and TL-WR902AC firmware versions prior to 'TL-WR902AC(JP)_V3_230506'. TP-LINK Technologies of TL-WR902AC firmware, TL-WR802N firmware, TL-WR841N The firmware has OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202309-1992 | CVE-2023-30725 |
CVSS V2: - CVSS V3: 5.5 Severity: MEDIUM |
Improper authentication in LocalProvier of Gallery prior to version 14.5.01.2 allows attacker to access the data in content provider.
| VAR-202309-2411 | CVE-2023-30724 |
CVSS V2: - CVSS V3: 3.3 Severity: LOW |
Improper authentication in GallerySearchProvider of Gallery prior to version 14.5.01.2 allows attacker to access search history.
| VAR-202309-2095 | No CVE | Zhuhai Pantum Printing Technology Co., Ltd. Pantum M6700DW Series has a logic defect vulnerability |
CVSS V2: 6.4 CVSS V3: - Severity: MEDIUM |
Zhuhai Pantum Printing Technology Co., Ltd. is an enterprise that masters the core technology of printers and independent intellectual property rights, and integrates R&D, design, production and sales of printers, consumables and text printing output solutions.
Zhuhai Pantum Printing Technology Co., Ltd. Pantum M6700DW Series has a logic flaw vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202309-1933 | No CVE | TP-LINK TL-WR841N has a binary vulnerability |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
TP-LINK TL-WR841N is a classic 11n wireless router under TP-Link.
There is a binary vulnerability in TP-LINK TL-WR841N, which can be used by attackers to cause denial of service attacks.
| VAR-202309-0548 | CVE-2023-20250 |
CVSS V2: - CVSS V3: 7.2 Severity: HIGH |
A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device.
This vulnerability is due to improper validation of requests that are sent to the web-based management interface. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary code with root privileges on an affected device. To exploit this vulnerability, the attacker must have valid Administrator credentials on the affected device