VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202504-2061 No CVE HPE OfficeConnect Switch 1820 48G PoE+ (370W) J9984A of Hewlett Packard Enterprise (China) Co., Ltd. has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
HPE (China) Co., Ltd. is a company mainly engaged in the research and development, production and manufacturing of computer hardware, software and its peripherals, and operates related electronic products. HPE OfficeConnect Switch 1820 48G PoE+ (370W) J9984A of HPE (China) Co., Ltd. has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202504-2263 No CVE Wuxi Xinjie Electric Co., Ltd. Xinjie XS3-26T4 PLC has industrial control equipment vulnerability CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
Wuxi Xinjie Electric Co., Ltd. is a listed company that focuses on the research and development and application of industrial automation products. Wuxi Xinjie Electric Co., Ltd. Xinjie XS3-26T4 PLC has an industrial control equipment vulnerability, which can be exploited by attackers to cause denial of service.
VAR-202504-2060 No CVE ZAVIOZAVIO F531E###ZAVIO F511W has an unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
ZAVIO F531 and ZAVIO F511W have an unauthorized access vulnerability that can be exploited by attackers to obtain sensitive information.
VAR-202504-1235 No CVE Ricoh (China) Investment Co., Ltd. SP C261SFNw has an unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
SP C261SFNw is a color laser multifunction printer launched by Ricoh. Ricoh (China) Investment Co., Ltd. SP C261SFNw has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202504-1635 No CVE Brother (China) Commercial Co., Ltd. DCP-1610W series has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
DCP-1610W series wireless black and white laser multifunction printer. Brother (China) Commercial Co., Ltd. DCP-1610W series has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202504-1431 No CVE Shenzhen Jixiang Tengda Technology Co., Ltd. AC6 has a binary vulnerability CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
AC6 is an 11ac dual-band wireless router designed for 100M fiber homes. AC6 of Shenzhen Jixiang Tengda Technology Co., Ltd. has a binary vulnerability that can be exploited by attackers to cause a denial of service.
VAR-202504-2259 No CVE TP-LINK TL-WR841ND has a denial of service vulnerability CVSS V2: 4.3
CVSS V3: -
Severity: MEDIUM
TP-LINK TL-WR841ND is a wireless router from TP-LINK of China. TP-LINK TL-WR841ND has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service.
VAR-202504-1852 No CVE RICOH MP C4504ex of Ricoh (China) Investment Co., Ltd. has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
RICOH MP C4504ex is a printer product. RICOH MP C4504ex of Ricoh (China) Investment Co., Ltd. has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202504-1430 No CVE Toshiba e-STUDIO2020AC has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
e-STUDIO2020AC is a printer. Toshiba e-STUDIO2020AC has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202504-0693 CVE-2025-3259 Shenzhen Tenda Technology Co.,Ltd.  of  RX3  Out-of-bounds write vulnerability in firmware CVSS V2: 9.0
CVSS V3: 8.8
Severity: High
A vulnerability, which was classified as critical, has been found in Tenda RX3 16.03.13.11. This issue affects the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Shenzhen Tenda Technology Co.,Ltd. of RX3 An out-of-bounds write vulnerability exists in firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Attackers can exploit this vulnerability to cause a denial of service or execute arbitrary code
VAR-202504-0695 CVE-2025-3237 Tenda FH1202 Improper Access Control Vulnerability CVSS V2: 5.0
CVSS V3: 5.3
Severity: Medium
A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been rated as critical. This issue affects some unknown processing of the file /goform/wrlwpsset. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Tenda FH1202 is a wireless router produced by China's Tenda Corporation. Attackers can use this vulnerability to launch remote attacks to gain access rights
VAR-202504-0831 CVE-2025-3203 Shenzhen Tenda Technology Co.,Ltd.  of  w18e  Out-of-bounds write vulnerability in firmware CVSS V2: 4.0
CVSS V3: 4.3
Severity: Medium
A vulnerability classified as problematic was found in Tenda W18E 16.01.0.11. Affected by this vulnerability is the function formSetAccountList of the file /goform/setModules. The manipulation of the argument Password leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Shenzhen Tenda Technology Co.,Ltd. of w18e An out-of-bounds write vulnerability exists in firmware.Service operation interruption (DoS) It may be in a state
VAR-202504-2260 No CVE HP Color LaserJet Pro MFP M479fdw of HP Trading (Shanghai) Co., Ltd. has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
HP Color LaserJet Pro MFP M479fdw is a wireless color laser printer. HP Color LaserJet Pro MFP M479fdw of HP Trading (Shanghai) Co., Ltd. has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202504-1636 No CVE SATO CL4NX-JPlus has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
CL4NX-Jplus is a smart barcode printer. SATO CL4NX-JPlus has a weak password vulnerability that can be exploited by attackers to obtain sensitive information.
VAR-202504-1209 CVE-2025-29462 Shenzhen Tenda Technology Co.,Ltd.  of  AC15  Classic buffer overflow vulnerability in firmware CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
A buffer overflow vulnerability has been discovered in Tenda Ac15 V15.13.07.13. The vulnerability occurs when the webCgiGetUploadFile function calls the socketRead function to process HTTP request messages, resulting in the overwriting of a buffer on the stack. Shenzhen Tenda Technology Co.,Ltd. of AC15 Firmware has a classic buffer overflow vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202504-0700 CVE-2025-3167 Shenzhen Tenda Technology Co.,Ltd.  of  ac23  Improper Shutdown and Release of Resources in Firmware Vulnerability CVSS V2: 6.8
CVSS V3: 6.5
Severity: High
A vulnerability, which was classified as problematic, has been found in Tenda AC23 16.03.07.52. This issue affects some unknown processing of the file /goform/VerAPIMant of the component API Interface. The manipulation of the argument getuid leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Shenzhen Tenda Technology Co.,Ltd. of ac23 A vulnerability exists in firmware related to improper shutdown and release of resources.Service operation interruption (DoS) It may be in a state. AC23 is a wireless router that provides high-speed wireless network connection. The vulnerability is caused by the improper processing of getuid parameters by the /goform/VerAPIMant component. An attacker can use this vulnerability to send specially crafted requests to cause a denial of service
VAR-202504-0028 CVE-2025-3161 Shenzhen Tenda Technology Co.,Ltd.  of  AC10  Buffer error vulnerability in firmware CVSS V2: 9.0
CVSS V3: 8.8
Severity: High
A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. This issue affects the function ShutdownSetAdd of the file /goform/ShutdownSetAdd. The manipulation of the argument list leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Shenzhen Tenda Technology Co.,Ltd. of AC10 The firmware contains a buffer error vulnerability, a stack-based buffer overflow vulnerability, and an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Tenda AC10 is a home wireless router that provides wireless network connection and management functions. The vulnerability stems from the improper processing of the list parameter by the ShutdownSetAdd function in the /goform/ShutdownSetAdd file. An attacker can exploit this vulnerability to launch a remote attack, achieve a stack overflow, and then execute arbitrary code
VAR-202504-1854 No CVE Schneider Electric (China) Co., Ltd. Schneider M340 has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Schneider M340 is a high-performance mid-range PLC platform launched by Schneider Electric. Schneider M340 of Schneider Electric (China) Co., Ltd. has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202504-1853 No CVE HP LaserJet MFP M132nw of HP Trading (Shanghai) Co., Ltd. has a command execution vulnerability CVSS V2: 7.5
CVSS V3: -
Severity: HIGH
HP LaserJet MFP M132nw is a multifunctional black and white laser printer. HP LaserJet MFP M132nw of HP Trading (Shanghai) Co., Ltd. has a command execution vulnerability, which can be exploited by attackers to execute arbitrary printer commands.
VAR-202504-2261 No CVE Shenzhen Jixiang Tengda Technology Co., Ltd. AC8 has a binary vulnerability CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
AC8 is a dual-band 3G wireless router suitable for fiber-optic homes within 1000M, supporting Gigabit ports, intelligent frequency selection, parental control and other functions. Shenzhen Jixiang Tengda Technology Co., Ltd. AC8 router has a binary vulnerability that can be exploited by attackers to cause a denial of service.