VARIoT IoT vulnerabilities database
| VAR-202606-2314 | CVE-2026-0418 | of netgear CBR750 Multiple vulnerabilities in multiple products, including firmware |
CVSS V2: - CVSS V3: 4.5 Severity: Medium |
Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network
to tamper with the system. • All information handled by this software may be overwritten. • This software will not stop
| VAR-202606-4135 | CVE-2026-0417 | of netgear MR60 Vulnerabilities related to input validation in multiple products, such as firmware |
CVSS V2: - CVSS V3: 4.5 Severity: Medium |
Insufficient input validation vulnerability in the listed NETGEAR devices allows
authenticated administrators connected to the local network to tamper with
the router's integrity. • All information handled by this software may be overwritten. • This software will not stop
| VAR-202606-2103 | CVE-2026-0415 | of netgear RBE970 FIRMWARE Vulnerabilities related to input confirmation in multiple products such as |
CVSS V2: - CVSS V3: 4.5 Severity: MEDIUM |
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality. • All information handled by this software may be overwritten. • This software will not stop
| VAR-202606-3181 | CVE-2026-0413 | of netgear RBE370 FIRMWARE Stack-based buffer overflow vulnerability in multiple products, including |
CVSS V2: - CVSS V3: 4.5 Severity: MEDIUM |
A buffer overflow vulnerability due to insufficient input validation in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality. • All information handled by this software may be overwritten. • This software will not stop
| VAR-202606-2758 | CVE-2026-0412 | of netgear JR6150 Firmware Input Validation Vulnerability |
CVSS V2: - CVSS V3: 4.5 Severity: Medium |
Insufficient input validation vulnerability in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows administrators connected to the local network to make unauthorized modification of router software and functionality. NETGEAR JR6150 reached End-of-Support status in 2018 and is no longer receiving security updates. NETGEAR strongly recommends
replacing these devices with newer NETGEAR models to ensure continued
security support and updates.
This vulnerability has been identified through firmware emulation in a
controlled research environment and has not been verified on production
hardware. • All information handled by this software may be overwritten. • This software will not stop
| VAR-202606-2972 | CVE-2026-0410 | of netgear R7000 Vulnerabilities related to input validation in multiple products, such as firmware |
CVSS V2: - CVSS V3: 4.5 Severity: MEDIUM |
Authenticated administrators connected to the local network can gain
elevated access to the router and make unauthorized changes to router
software and functionality. • All information handled by this software may be overwritten. • This software will not stop
| VAR-202606-1595 | CVE-2026-25089 | fortinet's FortiSandbox In multiple products such as OS Command injection vulnerability |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. This vulnerability allows an unauthenticated attacker to use a specially crafted attacker. HTTP It may be possible to execute malicious commands through the request.- All information handled by the software may be leaked to external parties. - All information handled by the software may be overwritten. - The software may completely shut down
| VAR-202606-0053 | CVE-2026-46749 | Siemens' SINEC INS predictable in Salt One-Way Hash Usage Vulnerability |
CVSS V2: - CVSS V3: 7.5 Severity: Medium |
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implementation with a static, hardcoded salt shared across all users and installations, and is configured with an insufficient number of iterations. This could allow an attacker to efficiently recover user passwords using brute-force or precomputed attacks, potentially resulting in unauthorized access. - All information handled by the software may be overwritten. - The software may completely shut down
| VAR-202606-0051 | CVE-2026-46748 | Siemens' SINEC INS Unnecessary Privileged Execution Vulnerability in |
CVSS V2: - CVSS V3: 8.8 Severity: High |
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected system includes a binary that is configured with the cap_dac_override capability. This capability allows the process to bypass file system permission checks, resulting in unrestricted file system access. This could allow a local attacker to escalate privileges leading to arbitrary file modification and gaining root privileges on the system. root It is possible to obtain the necessary permissions.- All information handled by the software may be leaked to external parties. - All information handled by the software may be overwritten. - The software may completely shut down
| VAR-202606-0054 | CVE-2026-46747 | Siemens' SINEC INS Past traversal vulnerability in |
CVSS V2: - CVSS V3: 4.3 Severity: Medium |
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application does not properly sanitize path input in the `GET /api/sftp/uploadFiles` endpoint used for directory listing. This allows path traversal through crafted input, enabling access to unintended file system locations. - No rewriting will occur to the information handled by the software. - The software will not stop
| VAR-202606-0052 | CVE-2026-46746 | Siemens' SINEC INS In OS Command injection vulnerability |
CVSS V2: - CVSS V3: 8.8 Severity: High |
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The application does not properly sanitize user input in the /api/sftp/uploadFiles endpoint, allowing the injection of shell command payloads via crafted directory names. These payloads are stored and executed when directory listings are retrieved. This could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system with the privileges of the affected service user (sinecins). - All information handled by the software may be overwritten. - The software may completely shut down
| VAR-202606-0933 | CVE-2026-11492 | D-Link Corporation of DIR-823G Multiple vulnerabilities in firmware |
CVSS V2: 4.0 CVSS V3: 4.3 Severity: Low |
A security flaw has been discovered in D-Link DIR-823G 1.0.2B05. The affected element is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Performing a manipulation results in least privilege violation. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. Techniques exploiting this vulnerability have been publicly disclosed and could be used in attacks.- All information handled by the software may be leaked to external parties. - All information handled by the software may be overwritten. - The software may completely shut down
| VAR-202606-1108 | CVE-2026-20245 | Cisco Systems Cisco Catalyst SD-WAN Manager Vulnerabilities related to encoding and escaping in multiple products such as the above. |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to perform command injection attacks on an affected system and elevate their privileges as the root user.
To exploit this vulnerability, the attacker must have netadmin privileges on the affected system. This would require valid credentials or exploitation of or . Cisco is not aware of successful exploitation by other methods. Cisco has observed limited cases where the exploitation of this bug resulted in a configuration change pushed to edge devices.
Cisco recommends that customers upgrade to the fixed software that is documented in the that was published on May 14, 2026, and verify the configuration of the edge devices. root It may be possible to execute arbitrary commands with the appropriate privileges. root It is possible to elevate privileges as a user. - All information handled by the software may be overwritten. - The software may completely shut down
| VAR-202606-1867 | CVE-2026-1871 | TP-LINK Technologies of tapo c200 Stack-based buffer overflow vulnerability in firmware |
CVSS V2: - CVSS V3: 6.5 Severity: MEDIUM |
TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header field lengths, which can be triggered by a crafted authentication request.
Successful exploitation causes the affected RTSP core service process to crash and triggers an automatic system reboot, resulting in a denial of service (DoS) condition. This prevents legitimate users from accessing the camera’s live video stream or management interface until the service restarts. If this vulnerability is exploited, affected systems will be affected. - No information handled by the software will be rewritten. - The software may completely shut down
| VAR-202606-1002 | CVE-2026-35718 | VIVOTEK Inc. of Network Camera FD8136 Path traversal vulnerability in firmware |
CVSS V2: - CVSS V3: 6.5 Severity: MEDIUM |
A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmware 0300a allows authenticated attackers to read any file on the device via sending a crafted request. - No rewriting will occur to the information handled by the software. - The software will not stop
| VAR-202606-1526 | CVE-2026-35716 | VIVOTEK Inc. of Network Camera FD8136 Stack-based buffer overflow vulnerability in firmware |
CVSS V2: - CVSS V3: 6.3 Severity: MEDIUM |
A stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via an oversized n1 parameter in a POST request to the /cgi-bin/admin/setpm.cgi, /cgi-bin/admin/setmd.cgi, or /cgi-bin/admin/setmd_profile.cgi endpoint (all symlinks to the same binary). The parameter value is copied into a fixed-size 0xa4-byte stack buffer without bounds checking, overwriting the saved link register. The binary is compiled without stack canaries. The value of this parameter is fixed in size. - Some of the information handled by the software may be overwritten. - Some parts of the software may stop working
| VAR-202606-1001 | CVE-2026-30652 | VIVOTEK Inc. of Network Camera FD8136 Classic buffer overflow vulnerability in firmware |
CVSS V2: - CVSS V3: 8.8 Severity: HIGH |
A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. This flaw allows an authenticated attacker to execute arbitrary code as root on the device. - All information handled by the software may be overwritten. - The software may completely shut down
| VAR-202606-1876 | CVE-2026-30650 | VIVOTEK Inc. of Network Camera FD8136 Classic buffer overflow vulnerability in firmware |
CVSS V2: - CVSS V3: 8.8 Severity: HIGH |
A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. This flaw allows an authenticated attacker to execute arbitrary code as root on the device remotely. root This allows execution based on the available permissions.- All information handled by the software may be leaked to external parties. - All information handled by the software may be overwritten. - The software may completely shut down
| VAR-202606-1525 | CVE-2026-30649 | VIVOTEK Inc. of Network Camera FD8136 Stack-based buffer overflow vulnerability in firmware |
CVSS V2: - CVSS V3: 7.3 Severity: HIGH |
Buffer Overflow vulnerability in VIVOTEK INC FD8136-VVTK-0300a allows a remote attacker to execute arbitrary code via the set_getparam.cgi component. - Some of the information handled by the software may be overwritten. - Some parts of the software may stop working
| VAR-202606-1877 | CVE-2026-35717 | VIVOTEK Inc. of Network Camera FD8136 Stack-based buffer overflow vulnerability in firmware |
CVSS V2: - CVSS V3: 6.3 Severity: MEDIUM |
A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via a crafted POST request to the /cgi-bin/admin/export_language.cgi endpoint. The handler passes the attacker-controlled Content-Length value directly to fread() as the read size into a fixed-size 0x60-byte stack buffer, overwriting the saved link register. The binary is compiled without stack canaries. The handler is controlled by the attacker. - Some of the information handled by the software may be overwritten. - Some parts of the software may stop working