VARIoT IoT vulnerabilities database
| VAR-202308-3761 | No CVE | Several products of Beijing StarNet Ruijie Network Technology Co., Ltd. have command execution vulnerabilities (CNVD-2023-68249) |
CVSS V2: 10.0 CVSS V3: - Severity: HIGH |
Beijing Xingwang Ruijie Network Technology Co., Ltd. is an ICT infrastructure and industry solution provider.
Several products of Beijing Xingwang Ruijie Network Technology Co., Ltd. have command execution vulnerabilities that attackers can use to gain server permissions.
| VAR-202308-4313 | No CVE | Buffer overflow vulnerability exists in H3C B6 of H3C Technology Co., Ltd. |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
H3C B6 Gigabit dual-band router is a newly designed Wi-Fi 6 home wireless smart router by H3C Intelligent Terminal Co., Ltd.
H3C B6 of New H3C Technology Co., Ltd. has a buffer overflow vulnerability. An attacker can use the vulnerability to trigger a stack overflow.
| VAR-202308-4325 | No CVE | There is a binary vulnerability in H3C-R230 of H3C Technology Co., Ltd. |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
H3C R230 is a home wireless router.
There is a binary vulnerability in H3C-R230 of H3C Technology Co., Ltd., which can be used by attackers to trigger stack overflow.
| VAR-202308-3431 | CVE-2023-40796 | PHICOMM of k2 Command injection vulnerability in firmware |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
Phicomm k2 v22.6.529.216 was discovered to contain a command injection vulnerability via the function luci.sys.call. (DoS) It may be in a state
| VAR-202308-3487 | CVE-2023-39290 | Mitel Networks Corporation of MiVoice Connect Vulnerability in |
CVSS V2: - CVSS V3: 4.9 Severity: MEDIUM |
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through R19.3 SP3 (22.24.5800.0) could allow an authenticated attacker with elevated privileges to conduct an information disclosure attack due to improper configuration. A successful exploit could allow an attacker to view system information. Mitel Networks Corporation of MiVoice Connect Exists in unspecified vulnerabilities.Information may be obtained
| VAR-202308-3159 | CVE-2023-39288 | Mitel Networks Corporation of MiVoice Connect Vulnerability in inserting or changing arguments in |
CVSS V2: - CVSS V3: 5.5 Severity: MEDIUM |
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2304.102 could allow an authenticated attacker with elevated privileges and internal network access to conduct a command argument injection due to insufficient parameter sanitization. A successful exploit could allow an attacker to access network information and to generate excessive network traffic. Mitel Networks Corporation of MiVoice Connect Exists in a vulnerability in inserting or modifying arguments.Information is obtained and service operation is interrupted (DoS) It may be in a state
| VAR-202308-3146 | CVE-2023-4542 | D-Link Systems, Inc. of dar-8000-10 in the firmware OS Command injection vulnerability |
CVSS V2: 6.5 CVSS V3: 6.3 Severity: MEDIUM |
A vulnerability was found in D-Link DAR-8000-10 up to 20230809. It has been classified as critical. This affects an unknown part of the file /app/sys1.php. The manipulation of the argument cmd with the input id leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-238047. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. D-Link Systems, Inc. of dar-8000-10 The firmware has OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DAR-8000 is the Internet behavior audit gateway of China D-Link Company.
D-Link DAR-8000-10 version has an operating system command injection vulnerability. The vulnerability stems from the failure of the parameter id in the file /app/sys1.php to correctly filter special characters, commands, etc. in the constructed command. An attacker could exploit this vulnerability to cause arbitrary command execution
| VAR-202308-3268 | CVE-2023-39287 | Mitel Networks Corporation of MiVoice Connect Vulnerability in inserting or changing arguments in |
CVSS V2: - CVSS V3: 5.5 Severity: MEDIUM |
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an authenticated attacker with elevated privileges and internal network access to conduct a command argument injection due to insufficient parameter sanitization. A successful exploit could allow an attacker to access network information and to generate excessive network traffic. Mitel Networks Corporation of MiVoice Connect Exists in a vulnerability in inserting or modifying arguments.Information is obtained and service operation is interrupted (DoS) It may be in a state
| VAR-202308-3203 | CVE-2023-39289 | Mitel Networks Corporation of MiVoice Connect Vulnerability in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2208.101 could allow an unauthenticated attacker to conduct an account enumeration attack due to improper configuration. A successful exploit could allow an attacker to access system information. Mitel Networks Corporation of MiVoice Connect Exists in unspecified vulnerabilities.Information may be obtained
| VAR-202308-4331 | CVE-2023-35749 | D-Link Systems, Inc. of DAP-2622 Stack-based buffer overflow vulnerability in firmware |
CVSS V2: 8.3 CVSS V3: 8.8 Severity: HIGH |
D-Link DAP-2622 DDP Firmware Upgrade Filename Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the DDP service. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20077. D-Link Systems, Inc. (DoS) It may be in a state. D-Link DAP-2622 is a wireless access point device from D-Link, a Chinese company
| VAR-202308-3319 | CVE-2023-37325 | D-Link Systems, Inc. of DAP-2622 Vulnerability related to lack of authentication for critical functions in firmware |
CVSS V2: 4.8 CVSS V3: 5.4 Severity: MEDIUM |
D-Link DAP-2622 DDP Set SSID List Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to make unauthorized changes to device configuration on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the DDP service. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to manipulate wireless authentication settings. Was ZDI-CAN-20104. D-Link Systems, Inc. of DAP-2622 Firmware has a lack of authentication vulnerability for critical functionality.Information is tampered with and service operation is interrupted (DoS) It may be in a state. D-Link DAP-2622 is a wireless access point device from D-Link, a Chinese company. No detailed vulnerability details are currently provided
| VAR-202308-3185 | CVE-2023-35741 | D-Link Systems, Inc. of DAP-2622 Out-of-bounds write vulnerability in firmware |
CVSS V2: 8.3 CVSS V3: 8.8 Severity: HIGH |
D-Link DAP-2622 DDP Configuration Backup Filename Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the DDP service. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20068. D-Link Systems, Inc. of DAP-2622 An out-of-bounds write vulnerability exists in firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DAP-2622 is a wireless access point device from D-Link, a Chinese company
| VAR-202308-3103 | CVE-2023-35750 | D-Link Systems, Inc. of DAP-2622 Firmware vulnerabilities |
CVSS V2: 6.1 CVSS V3: 7.4 Severity: HIGH |
D-Link DAP-2622 DDP Get SSID List WPA PSK Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the DDP service. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-20078. D-Link Systems, Inc. of DAP-2622 There are unspecified vulnerabilities in the firmware.Information may be obtained. The D-Link DAP-2622 is a wireless access point manufactured by D-Link, a Chinese company. It's primarily used for wireless network coverage in enterprises and public spaces
| VAR-202308-3111 | CVE-2023-37318 | D-Link Systems, Inc. of DAP-2622 Out-of-bounds write vulnerability in firmware |
CVSS V2: 8.3 CVSS V3: 8.8 Severity: HIGH |
D-Link DAP-2622 DDP Set IPv6 Address Secondary DNS Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the DDP service. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20096. D-Link Systems, Inc. of DAP-2622 An out-of-bounds write vulnerability exists in firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The D-Link DAP-2622 is a wireless access point (AP) from D-Link that supports PoE power supply and is primarily used for wireless network coverage in enterprise or commercial settings
| VAR-202308-3228 | CVE-2023-40802 | Shenzhen Tenda Technology Co.,Ltd. of ac23 Out-of-bounds write vulnerability in firmware |
CVSS V2: 6.8 CVSS V3: 6.5 Severity: MEDIUM |
The get_parentControl_list_Info function does not verify the parameters entered by the user, causing a post-authentication heap overflow vulnerability in Tenda AC23 v16.03.07.45_cn. Shenzhen Tenda Technology Co.,Ltd. of ac23 An out-of-bounds write vulnerability exists in firmware.Service operation interruption (DoS) It may be in a state. The Tenda AC23 is a dual-band wireless router for home use launched by Tenda, designed for coverage in large homes and high-speed transmission. It supports 802.11acWave2 technology and has a maximum concurrent dual-band speed of 2033Mbps. Detailed vulnerability information is currently unavailable
| VAR-202308-3664 | CVE-2023-41215 | D-Link Systems, Inc. of DAP-2622 Out-of-bounds write vulnerability in firmware |
CVSS V2: 8.3 CVSS V3: 8.8 Severity: HIGH |
D-Link DAP-2622 DDP Set Date-Time Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the DDP service. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20086. D-Link Systems, Inc. of DAP-2622 An out-of-bounds write vulnerability exists in firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The D-Link DAP-2622 is a wireless access point (AP) from D-Link that supports PoE power supply and is primarily used for wireless network coverage in enterprise or commercial settings
| VAR-202308-3131 | CVE-2023-35732 | D-Link Systems, Inc. of DAP-2622 Out-of-bounds write vulnerability in firmware |
CVSS V2: 8.3 CVSS V3: 8.8 Severity: HIGH |
D-Link DAP-2622 DDP Reset Factory Auth Password Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the DDP service. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20059. D-Link Systems, Inc. of DAP-2622 An out-of-bounds write vulnerability exists in firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DAP-2622 is a wireless access point device from D-Link, a Chinese company
| VAR-202308-3128 | CVE-2023-37311 | D-Link Systems, Inc. of DAP-2622 Out-of-bounds write vulnerability in firmware |
CVSS V2: 7.2 CVSS V3: 8.8 Severity: HIGH |
D-Link DAP-2622 DDP Set Device Info Auth Password Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the DDP service. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20088. D-Link Systems, Inc. of DAP-2622 An out-of-bounds write vulnerability exists in firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The D-Link DAP-2622 is a wireless access point (AP) from D-Link that supports PoE power supply and is primarily used for wireless network coverage in enterprise or commercial settings
| VAR-202308-3252 | CVE-2023-37310 | D-Link Systems, Inc. of DAP-2622 Out-of-bounds write vulnerability in firmware |
CVSS V2: 8.3 CVSS V3: 8.8 Severity: HIGH |
D-Link DAP-2622 DDP Set Device Info Auth Username Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the DDP service. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20087. D-Link Systems, Inc. of DAP-2622 An out-of-bounds write vulnerability exists in firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The D-Link DAP-2622 is a wireless access point (AP) from D-Link that supports PoE power supply and is primarily used for wireless network coverage in enterprise or commercial settings
| VAR-202308-3136 | CVE-2023-35753 | D-Link Systems, Inc. of DAP-2622 Out-of-bounds write vulnerability in firmware |
CVSS V2: 8.3 CVSS V3: 8.8 Severity: HIGH |
D-Link DAP-2622 DDP Set AG Profile UUID Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the DDP service. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20081. D-Link Systems, Inc. of DAP-2622 An out-of-bounds write vulnerability exists in firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The D-Link DAP-2622 is a wireless access point (AP) from D-Link that supports PoE power supply and is primarily used for wireless network coverage in enterprise or commercial settings