VARIoT IoT vulnerabilities database
| VAR-202302-0453 | CVE-2023-24276 | TOTOLINK A7100RU Command injection vulnerability |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the country parameter at setting/delStaticDhcpRules
| VAR-202302-0439 | CVE-2022-28923 | Caddy Open redirect vulnerability in |
CVSS V2: - CVSS V3: 6.1 Severity: MEDIUM |
Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs. Caddy Exists in an open redirect vulnerability.Information may be obtained and information may be tampered with
| VAR-202302-0355 | CVE-2022-48166 | WAVLINK WL-WN530HG4 Security hole |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
An access control issue in Wavlink WL-WN530HG4 M30HG4.V5030.201217 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials
| VAR-202302-0456 | CVE-2022-48289 | EMUI and HarmonyOS Vulnerability regarding lack of authentication for critical features in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality. EMUI and HarmonyOS There is a vulnerability in the lack of authentication for critical features.Information may be obtained
| VAR-202302-0433 | CVE-2022-48286 | EMUI and HarmonyOS Vulnerability in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
The multi-screen collaboration module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. EMUI and HarmonyOS Exists in unspecified vulnerabilities.Information may be obtained
| VAR-202302-0368 | CVE-2022-48288 | EMUI and HarmonyOS Vulnerability regarding lack of authentication for critical features in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality. EMUI and HarmonyOS There is a vulnerability in the lack of authentication for critical features.Information may be obtained
| VAR-202302-0393 | CVE-2022-48292 | EMUI and HarmonyOS Out-of-bounds read vulnerability in |
CVSS V2: - CVSS V3: 6.5 Severity: MEDIUM |
The Bluetooth module has an out-of-memory (OOM) vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. EMUI and HarmonyOS Exists in an out-of-bounds read vulnerability.Information may be obtained
| VAR-202302-0414 | CVE-2022-48294 | EMUI and HarmonyOS Authentication vulnerability in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
The IHwAttestationService interface has a defect in authentication. Successful exploitation of this vulnerability may affect data confidentiality. EMUI and HarmonyOS There is an authentication vulnerability in.Information may be obtained
| VAR-202302-0392 | CVE-2022-48295 | EMUI and HarmonyOS Improper Permission Preservation Vulnerability in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
The IHwAntiMalPlugin interface lacks permission verification. Successful exploitation of this vulnerability can lead to filling problems (batch installation of applications). EMUI and HarmonyOS contains an improper permissions retention vulnerability.Information may be tampered with
| VAR-202302-0467 | CVE-2022-48298 | EMUI and HarmonyOS Improper Validation of Quantities Specified in Inputs in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
The geofencing kernel code does not verify the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access. EMUI and HarmonyOS contains a vulnerability related to improper validation of quantities specified in inputs.Information may be obtained
| VAR-202302-0469 | CVE-2022-48287 | EMUI and HarmonyOS Vulnerability in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data integrity. EMUI and HarmonyOS Exists in unspecified vulnerabilities.Information may be tampered with
| VAR-202302-0455 | CVE-2022-48297 | EMUI and HarmonyOS Improper Validation of Quantities Specified in Inputs in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
The geofencing kernel code has a vulnerability of not verifying the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access. EMUI and HarmonyOS contains a vulnerability related to improper validation of quantities specified in inputs.Information may be obtained
| VAR-202302-0468 | CVE-2022-48293 | EMUI and HarmonyOS Out-of-bounds read vulnerability in |
CVSS V2: - CVSS V3: 6.5 Severity: MEDIUM |
The Bluetooth module has an OOM vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. EMUI and HarmonyOS Exists in an out-of-bounds read vulnerability.Information may be obtained
| VAR-202302-0316 | CVE-2022-48301 | EMUI and HarmonyOS Improper Permission Preservation Vulnerability in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
The bundle management module lacks permission verification in some APIs. Successful exploitation of this vulnerability may restore the pre-installed apps that have been uninstalled. EMUI and HarmonyOS contains an improper permissions retention vulnerability.Information may be tampered with
| VAR-202302-0315 | CVE-2022-48299 | EMUI and HarmonyOS Vulnerability regarding lack of authentication for critical features in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality. EMUI and HarmonyOS There is a vulnerability in the lack of authentication for critical features.Information may be obtained
| VAR-202302-0346 | CVE-2022-48300 | EMUI and HarmonyOS Vulnerability regarding lack of authentication for critical features in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality. EMUI and HarmonyOS There is a vulnerability in the lack of authentication for critical features.Information may be obtained
| VAR-202302-0347 | CVE-2022-48290 | HarmonyOS Vulnerability in |
CVSS V2: - CVSS V3: 9.1 Severity: CRITICAL |
The phone-PC collaboration module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality and integrity. HarmonyOS Exists in unspecified vulnerabilities.Information may be obtained and information may be tampered with
| VAR-202302-0369 | CVE-2022-48302 | EMUI and HarmonyOS Vulnerability in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
The AMS module has a vulnerability of lacking permission verification in APIs.Successful exploitation of this vulnerability may affect data confidentiality. EMUI and HarmonyOS Exists in unspecified vulnerabilities.Information may be obtained
| VAR-202302-0317 | CVE-2022-48296 | EMUI and HarmonyOS Improper Permission Preservation Vulnerability in |
CVSS V2: - CVSS V3: 5.3 Severity: MEDIUM |
The SystemUI has a vulnerability in permission management. Successful exploitation of this vulnerability may cause users to receive broadcasts from malicious apps, conveying false alarm information about external storage devices. EMUI and HarmonyOS contains an improper permissions retention vulnerability.Information may be tampered with
| VAR-202302-0251 | CVE-2023-24157 | TOTOLINK T8 Command injection vulnerability in |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
A command injection vulnerability in the serverIp parameter in the function updateWifiInfo of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet. TOTOLINK T8 Contains a command injection vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The TOTOLINK T8 is a wireless dual-band router primarily used for network connectivity and data transmission