VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202302-0453 CVE-2023-24276 TOTOLINK A7100RU Command injection vulnerability CVSS V2: -
CVSS V3: 9.8
Severity: CRITICAL
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the country parameter at setting/delStaticDhcpRules
VAR-202302-0439 CVE-2022-28923 Caddy  Open redirect vulnerability in CVSS V2: -
CVSS V3: 6.1
Severity: MEDIUM
Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs. Caddy Exists in an open redirect vulnerability.Information may be obtained and information may be tampered with
VAR-202302-0355 CVE-2022-48166 WAVLINK WL-WN530HG4 Security hole CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
An access control issue in Wavlink WL-WN530HG4 M30HG4.V5030.201217 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials
VAR-202302-0456 CVE-2022-48289 EMUI  and  HarmonyOS  Vulnerability regarding lack of authentication for critical features in CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality. EMUI and HarmonyOS There is a vulnerability in the lack of authentication for critical features.Information may be obtained
VAR-202302-0433 CVE-2022-48286 EMUI  and  HarmonyOS  Vulnerability in CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
The multi-screen collaboration module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. EMUI and HarmonyOS Exists in unspecified vulnerabilities.Information may be obtained
VAR-202302-0368 CVE-2022-48288 EMUI  and  HarmonyOS  Vulnerability regarding lack of authentication for critical features in CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality. EMUI and HarmonyOS There is a vulnerability in the lack of authentication for critical features.Information may be obtained
VAR-202302-0393 CVE-2022-48292 EMUI  and  HarmonyOS  Out-of-bounds read vulnerability in CVSS V2: -
CVSS V3: 6.5
Severity: MEDIUM
The Bluetooth module has an out-of-memory (OOM) vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. EMUI and HarmonyOS Exists in an out-of-bounds read vulnerability.Information may be obtained
VAR-202302-0414 CVE-2022-48294 EMUI  and  HarmonyOS  Authentication vulnerability in CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
The IHwAttestationService interface has a defect in authentication. Successful exploitation of this vulnerability may affect data confidentiality. EMUI and HarmonyOS There is an authentication vulnerability in.Information may be obtained
VAR-202302-0392 CVE-2022-48295 EMUI  and  HarmonyOS  Improper Permission Preservation Vulnerability in CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
The IHwAntiMalPlugin interface lacks permission verification. Successful exploitation of this vulnerability can lead to filling problems (batch installation of applications). EMUI and HarmonyOS contains an improper permissions retention vulnerability.Information may be tampered with
VAR-202302-0467 CVE-2022-48298 EMUI  and  HarmonyOS  Improper Validation of Quantities Specified in Inputs in CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
The geofencing kernel code does not verify the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access. EMUI and HarmonyOS contains a vulnerability related to improper validation of quantities specified in inputs.Information may be obtained
VAR-202302-0469 CVE-2022-48287 EMUI  and  HarmonyOS  Vulnerability in CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data integrity. EMUI and HarmonyOS Exists in unspecified vulnerabilities.Information may be tampered with
VAR-202302-0455 CVE-2022-48297 EMUI  and  HarmonyOS  Improper Validation of Quantities Specified in Inputs in CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
The geofencing kernel code has a vulnerability of not verifying the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access. EMUI and HarmonyOS contains a vulnerability related to improper validation of quantities specified in inputs.Information may be obtained
VAR-202302-0468 CVE-2022-48293 EMUI  and  HarmonyOS  Out-of-bounds read vulnerability in CVSS V2: -
CVSS V3: 6.5
Severity: MEDIUM
The Bluetooth module has an OOM vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. EMUI and HarmonyOS Exists in an out-of-bounds read vulnerability.Information may be obtained
VAR-202302-0316 CVE-2022-48301 EMUI  and  HarmonyOS  Improper Permission Preservation Vulnerability in CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
The bundle management module lacks permission verification in some APIs. Successful exploitation of this vulnerability may restore the pre-installed apps that have been uninstalled. EMUI and HarmonyOS contains an improper permissions retention vulnerability.Information may be tampered with
VAR-202302-0315 CVE-2022-48299 EMUI  and  HarmonyOS  Vulnerability regarding lack of authentication for critical features in CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality. EMUI and HarmonyOS There is a vulnerability in the lack of authentication for critical features.Information may be obtained
VAR-202302-0346 CVE-2022-48300 EMUI  and  HarmonyOS  Vulnerability regarding lack of authentication for critical features in CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality. EMUI and HarmonyOS There is a vulnerability in the lack of authentication for critical features.Information may be obtained
VAR-202302-0347 CVE-2022-48290 HarmonyOS  Vulnerability in CVSS V2: -
CVSS V3: 9.1
Severity: CRITICAL
The phone-PC collaboration module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality and integrity. HarmonyOS Exists in unspecified vulnerabilities.Information may be obtained and information may be tampered with
VAR-202302-0369 CVE-2022-48302 EMUI  and  HarmonyOS  Vulnerability in CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
The AMS module has a vulnerability of lacking permission verification in APIs.Successful exploitation of this vulnerability may affect data confidentiality. EMUI and HarmonyOS Exists in unspecified vulnerabilities.Information may be obtained
VAR-202302-0317 CVE-2022-48296 EMUI  and  HarmonyOS  Improper Permission Preservation Vulnerability in CVSS V2: -
CVSS V3: 5.3
Severity: MEDIUM
The SystemUI has a vulnerability in permission management. Successful exploitation of this vulnerability may cause users to receive broadcasts from malicious apps, conveying false alarm information about external storage devices. EMUI and HarmonyOS contains an improper permissions retention vulnerability.Information may be tampered with
VAR-202302-0251 CVE-2023-24157 TOTOLINK T8  Command injection vulnerability in CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
A command injection vulnerability in the serverIp parameter in the function updateWifiInfo of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet. TOTOLINK T8 Contains a command injection vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The TOTOLINK T8 is a wireless dual-band router primarily used for network connectivity and data transmission