VARIoT IoT vulnerabilities database
| VAR-202306-0826 | CVE-2023-33536 | TP-Link wireless router Buffer error vulnerability |
CVSS V2: - CVSS V3: 8.1 Severity: HIGH |
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a buffer overflow via the component /userRpm/WlanMacFilterRpm
| VAR-202308-3142 | CVE-2023-25649 | ZTE of MF286R Command injection vulnerability in firmware |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_DEVICE_LED interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands. ZTE of MF286R Firmware contains a command injection vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Authentication is required to exploit this vulnerability.The specific flaw exists within the handling of a request parameter provided to the SET_DEVICE_LED endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. ZTE MF286R is a wireless router made by China's ZTE Corporation. This vulnerability is caused by the application's failure to correctly filter special characters and commands in constructed commands
| VAR-202306-0607 | CVE-2023-33533 | Netgear Router Command injection vulnerability |
CVSS V2: - CVSS V3: 8.8 Severity: HIGH |
Netgear D6220 with Firmware Version 1.0.0.80, D8500 with Firmware Version 1.0.3.60, R6700 with Firmware Version 1.0.2.26, and R6900 with Firmware Version 1.0.2.26 are vulnerable to Command Injection. If an attacker gains web management privileges, they can inject commands into the post request parameters, gaining shell privileges
| VAR-202306-0535 | CVE-2023-27126 | TP-LINK Tapo C200 Security hole |
CVSS V2: - CVSS V3: 4.6 Severity: MEDIUM |
The AES Key-IV pair used by the TP-Link TAPO C200 camera V3 (EU) on firmware version 1.1.22 Build 220725 is reused across all cameras. An attacker with physical access to a camera is able to extract and decrypt sensitive data containing the Wifi password and the TP-LINK account credential of the victim
| VAR-202306-0440 | CVE-2023-33532 | Netgear R6250 Command Injection Vulnerability |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
There is a command injection vulnerability in the Netgear R6250 router with Firmware Version 1.0.4.48. If an attacker gains web management privileges, they can inject commands into the post request parameters, thereby gaining shell privileges. Netgear R6250 is a router launched by Netgear. Attackers can use this vulnerability to execute arbitrary commands and obtain host privileges
| VAR-202306-0330 | CVE-2023-31569 | TOTOLINK X5000R Command injection vulnerability |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection via the setWanCfg function.
| VAR-202306-0596 | CVE-2023-33530 | Tenda G103 Command Injection Vulnerability (CNVD-2023-52857) |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
There is a command injection vulnerability in the Tenda G103 Gigabit GPON Terminal with firmware version V1.0.0.5. If an attacker gains web management privileges, they can inject commands gaining shell privileges. Tenda G103 is a GPON fiber access device specially designed for home and SOHO users by China Tenda Company. The vulnerability stems from the fact that the application fails to properly filter and construct commands with special characters, commands, etc
| VAR-202306-0278 | CVE-2022-48188 | Lenovo Desktops and ThinkStation Buffer error vulnerability |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local access to elevate their privileges to execute arbitrary code
| VAR-202306-0277 | CVE-2022-48181 | Lenovo ThinkPad Buffer error vulnerability |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
An ErrorMessage driver stack-based buffer overflow vulnerability in BIOS of some ThinkPad models could allow an attacker with local access to elevate their privileges and execute arbitrary code
| VAR-202306-0130 | CVE-2023-32628 | Advantech WebAccess/SCADA arbitrary file upload vulnerability (CNVD-2024-15541) |
CVSS V2: 9.0 CVSS V3: 9.8 Severity: CRITICAL |
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to modify the file extension of a certificate file to ASP when uploading it, which can lead to remote code execution. Advantech WebAccess/SCADA is a set of SCADA software based on browser architecture from China Advantech Company. The software supports dynamic graphic display and real-time data control, and provides remote control and management of automation equipment
| VAR-202306-0131 | CVE-2023-22450 | Advantech WebAccess/SCADA Arbitrary File Upload Vulnerability |
CVSS V2: 9.0 CVSS V3: 7.2 Severity: HIGH |
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to upload an ASP script file to a webserver when logged in as manager user, which can lead to arbitrary code execution. Advantech WebAccess/SCADA is a set of SCADA software based on browser architecture from China Advantech Company. The software supports dynamic graphic display and real-time data control, and provides remote control and management of automation equipment. This vulnerability is caused by the application's lack of effective verification of uploaded files
| VAR-202306-0129 | CVE-2023-29160 | Made by Fuji Electric FRENIC RHC Loader Multiple vulnerabilities in |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
Stack-based buffer overflow vulnerability exists in FRENIC RHC Loader v1.1.0.3. If a user opens a specially crafted FNE file, sensitive information on the system where the affected product is installed may be disclosed or arbitrary code may be executed. Provided by Fuji Electric Co., Ltd. FRENIC RHC Loader contains multiple vulnerabilities: * stack-based buffer overflow ( CWE-121 ) - CVE-2023-29160 It was * out-of-bounds read ( CWE-125 ) - CVE-2023-29167 It was * XML External entity reference ( XXE ) inappropriate restriction ( CWE-611 ) - CVE-2023-29498 This vulnerability information is JPCERT/CC Report to JPCERT/CC Coordinated with the developer. Fuji Electric FRENIC RHC Loader is a software tool developed by Fuji Electric in Japan for debugging and monitoring inverters, primarily serving the industrial automation sector
| VAR-202306-0152 | CVE-2022-47617 | Hitron Technologies Inc. of coda-5310 Vulnerability related to use of hardcoded credentials in firmware |
CVSS V2: - CVSS V3: 7.2 Severity: HIGH |
Hitron CODA-5310 has hard-coded encryption/decryption keys in the program code. A remote attacker authenticated as an administrator can decrypt system files using the hard-coded keys for file access, modification, and cause service disruption. Hitron Technologies Inc. of coda-5310 A vulnerability exists in the firmware regarding the use of hardcoded credentials.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202306-0116 | CVE-2023-33675 | Shenzhen Tenda Technology Co.,Ltd. of AC8 Out-of-bounds write vulnerability in firmware |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the get_parentControl_list_Info function. Shenzhen Tenda Technology Co.,Ltd. of AC8 An out-of-bounds write vulnerability exists in firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The Tenda AC8 is a dual-band gigabit wireless router designed for homes with fiber optic connections up to 1000 Mbps. It supports dual-band concurrent transmission rates of up to 1167 Mbps and is equipped with full gigabit ports (one WAN port and three LAN ports), meeting broadband access needs between 100 and 1000 Mbps. An attacker could exploit this vulnerability to execute arbitrary code on the system or cause a denial of service
| VAR-202306-0225 | CVE-2023-30602 | Hitron Technologies CODA Security hole |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
Hitron Technologies CODA-5310’s Telnet function transfers sensitive data in plaintext. An unauthenticated remote attacker can exploit this vulnerability to access credentials of normal users and administrator
| VAR-202306-0241 | CVE-2023-30604 | Hitron Technologies CODA Access control error vulnerability |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
It is identified a vulnerability of insufficient authentication in the system configuration interface of Hitron Technologies CODA-5310. An unauthorized remote attacker can exploit this vulnerability to access system configuration interface, resulting in performing arbitrary system operation or disrupt service
| VAR-202306-0114 | CVE-2023-33670 | Shenzhen Tenda Technology Co.,Ltd. of AC8 Out-of-bounds write vulnerability in firmware |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the sub_4a79ec function. Shenzhen Tenda Technology Co.,Ltd. of AC8 An out-of-bounds write vulnerability exists in firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The Tenda AC8 is a dual-band gigabit wireless router designed for homes with fiber optic connections up to 1000 Mbps. It supports dual-band concurrent transmission rates of up to 1167 Mbps and is equipped with full gigabit ports (one WAN port and three LAN ports), meeting broadband access needs between 100 and 1000 Mbps. An attacker could exploit this vulnerability to execute arbitrary code on the system or cause a denial of service
| VAR-202306-0128 | CVE-2023-29167 | Made by Fuji Electric FRENIC RHC Loader Multiple vulnerabilities in |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
Out-of-bound reads vulnerability exists in FRENIC RHC Loader v1.1.0.3. If a user opens a specially crafted FNE file, sensitive information on the system where the affected product is installed may be disclosed or arbitrary code may be executed. Provided by Fuji Electric Co., Ltd. FRENIC RHC Loader contains multiple vulnerabilities: * stack-based buffer overflow ( CWE-121 ) - CVE-2023-29160 It was * out-of-bounds read ( CWE-125 ) - CVE-2023-29167 It was * XML External entity reference ( XXE ) inappropriate restriction ( CWE-611 ) - CVE-2023-29498 This vulnerability information is JPCERT/CC Report to JPCERT/CC Coordinated with the developer. Fuji Electric FRENIC RHC Loader is a software tool developed by Fuji Electric in Japan for debugging and monitoring inverters, primarily serving the industrial automation sector
| VAR-202306-0187 | CVE-2022-47616 | Hitron Technologies Inc. of coda-5310 in the firmware OS Command injection vulnerability |
CVSS V2: 9.0 CVSS V3: 7.2 Severity: HIGH |
Hitron CODA-5310 has insufficient filtering for specific parameters in the connection test function. A remote attacker authenticated as an administrator, can use the management page to perform command injection attacks, to execute arbitrary system command, manipulate system or disrupt service. Hitron Technologies Inc. of coda-5310 The firmware has OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state.
Hitron Technologies CODA-5310 has a remote command execution vulnerability
| VAR-202306-0132 | CVE-2023-32540 | Advantech WebAccess/SCADA Arbitrary File Overwrite Vulnerability |
CVSS V2: 9.0 CVSS V3: 9.8 Severity: CRITICAL |
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an XLS file, and modify the file extension, which could lead to arbitrary code execution. Advantech WebAccess/SCADA is a set of SCADA software based on browser architecture from China Advantech Company. The software supports dynamic graphic display and real-time data control, and provides remote control and management of automation equipment