VARIoT IoT vulnerabilities database
| VAR-202203-1022 | CVE-2022-25548 | Tenda AX1806 stack overflow vulnerability |
CVSS V2: 7.8 CVSS V3: 7.5 Severity: HIGH |
Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the serverName parameter. Tenda AX1806 is a WiFi6 wireless router from Tenda, China.
A stack overflow vulnerability exists in Tenda AX1806, which allows remote attackers to use the vulnerability to submit special requests that can crash the application or execute arbitrary code in the context of the application
| VAR-202203-0319 | CVE-2022-25820 | Google of Android Vulnerability in improperly limiting excessive authentication attempts in |
CVSS V2: 2.1 CVSS V3: 4.6 Severity: MEDIUM |
A vulnerable design in fingerprint matching algorithm prior to SMR Mar-2022 Release 1 allows physical attackers to perform brute force attack on screen lock password. Google of Android Is vulnerable to improper restrictions on excessive authentication attempts.Information may be obtained. Samsung fingerprint matching algorithm is a fingerprint matching algorithm for Samsung mobile devices.
There is a design error vulnerability in the Samsung fingerprint matching algorithm. This vulnerability is due to the improper design of the failure counting algorithm
| VAR-202203-0280 | CVE-2021-44623 | TP-Link TL-WR886N stack overflow vulnerability (CNVD-2022-21167) |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 via the /cloud_config/router_post/check_reset_pwd_verify_code interface. TP-Link TL-WR886N is a wireless router from China Pulian Company.
The TP-Link TL-WR886N /cloud_config/router_post/check_reset_pwd_verify_code has a stack overflow vulnerability, which can be exploited by a remote attacker to submit a special request, which can crash the application or execute arbitrary code in the context of the application
| VAR-202203-0288 | CVE-2021-4045 |
Tp-link Tapo C200 Command Injection Vulnerability
Related entries in the VARIoT exploits database: VAR-E-202209-0076 |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd binary running by default as root. The exploitation of this vulnerability allows an attacker to take full control of the camera. TP-LINK Technologies of tapo c200 Firmware contains a command injection vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Tp-link Tapo C200 is a network camera device from Tp-link company in China. The vulnerability stems from the uhttpd binary that runs as root by default in the software, which lacks filtering and escaping of command parameters. An unauthenticated attacker could exploit this vulnerability to execute system commands on the system through a special command request
| VAR-202203-0872 | CVE-2021-38910 | IBM DataPower Gateway Input verification vulnerability in |
CVSS V2: 5.0 CVSS V3: 5.3 Severity: MEDIUM |
IBM DataPower Gateway V10CD, 10.0.1, and 2108.4.1 could allow a remote attacker to bypass security restrictions, caused by the improper validation of input. By sending a specially crafted JSON message, an attacker could exploit this vulnerability to modify structure and fields. IBM X-Force ID: 209824. Vendor exploits this vulnerability IBM X-Force ID: 209824 It is published as.Information may be tampered with
| VAR-202203-0323 | CVE-2022-25823 | Samsung's Android for Galaxy Watch Information disclosure vulnerability in plug-in |
CVSS V2: 2.1 CVSS V3: 3.3 Severity: LOW |
Information Exposure vulnerability in Galaxy Watch Plugin prior to version 2.2.05.220126741 allows attackers to access user information in log
| VAR-202203-1021 | CVE-2022-25546 | Tenda AX1806 Stack Overflow Vulnerability (CNVD-2022-22747) |
CVSS V2: 7.8 CVSS V3: 7.5 Severity: HIGH |
Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetSysToolDDNS. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ddnsUser parameter. Tenda AX1806 is a WiFi6 wireless router from Tenda, China
| VAR-202203-0281 | CVE-2021-44626 | TP-Link TL-WR886N Stack Overflow Vulnerability (CNVD-2022-20080) |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/get_reg_verify_code feature, which allows malicious users to execute arbitrary code on the system via a crafted post request. TP-Link TL-WR886N is a wireless router from China Pulian Company
| VAR-202203-0973 | CVE-2021-40055 | plural Huawei Product vulnerabilities |
CVSS V2: 7.1 CVSS V3: 5.9 Severity: MEDIUM |
There is a man-in-the-middle attack vulnerability during system update download in recovery mode. Successful exploitation of this vulnerability may affect integrity. Huawei of EMUI , HarmonyOS , Magic UI Exists in unspecified vulnerabilities.Information may be tampered with
| VAR-202203-0929 | CVE-2021-44625 | TP-Link TL-WR886N Stack Overflow Vulnerability (CNVD-2022-20081) |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in /cloud_config/cloud_device/info interface, which allows a malicious user to executee arbitrary code on the system via a crafted post request. TP-Link TL-WR886N is a wireless router from China Pulian Company
| VAR-202203-0261 | CVE-2021-40053 | plural Huawei Inappropriate Default Permission Vulnerability in Products |
CVSS V2: 6.4 CVSS V3: 9.1 Severity: CRITICAL |
There is a permission control vulnerability in the Nearby module.Successful exploitation of this vulnerability will affect availability and integrity. Huawei of EMUI , HarmonyOS , Magic UI There is a vulnerability in improper default permissions.Information is tampered with and service operation is interrupted (DoS) It may be in a state
| VAR-202203-0312 | CVE-2022-25550 | Tenda AX1806 saveParentControlInfo function stack overflow vulnerability (CNVD-2022-23525) |
CVSS V2: 7.8 CVSS V3: 7.5 Severity: HIGH |
Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function saveParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the deviceName parameter. Tenda AX1806 is a WiFi6 wireless router from China Tenda company
| VAR-202203-0263 | CVE-2021-40054 | Huawei of EMUI and Magic UI Integer Underflow Vulnerability in |
CVSS V2: 7.8 CVSS V3: 7.5 Severity: HIGH |
There is an integer underflow vulnerability in the atcmdserver module. Successful exploitation of this vulnerability may affect integrity. Huawei of EMUI and Magic UI Exists in an integer underflow vulnerability.Information may be tampered with
| VAR-202203-0258 | CVE-2020-14111 | mi of ax3600 Insufficient validation of data authenticity in firmware vulnerability |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection. Attackers can exploit this vulnerability to execute code. mi of ax3600 Firmware contains insufficient validation of data authenticity.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The Xiaomi router AX3600 is a router from the Chinese company Xiaomi
| VAR-202203-0316 | CVE-2022-25558 | Tenda AX1806 formSetProvince function stack overflow vulnerability |
CVSS V2: 7.8 CVSS V3: 7.5 Severity: HIGH |
Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetProvince. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ProvinceCode parameter. Tenda AX1806 is a WiFi6 wireless router from Tenda, China
| VAR-202203-0285 | CVE-2021-44632 | TP-Link TL-WR886N Buffer Overflow Vulnerability (CNVD-2022-20072) |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/upgrade_info feature, which allows malicious users to execute arbitrary code on the system via a crafted post request. TP-Link TL-WR886N is a wireless router from China Pulian Company.
A buffer overflow vulnerability exists in TP-Link TL-WR886N 20190826 version 2.3.8
| VAR-202203-1015 | CVE-2022-24995 | Shenzhen Tenda Technology Co.,Ltd. of AX3 Out-of-bounds write vulnerability in firmware |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the time parameter. Shenzhen Tenda Technology Co.,Ltd. of AX3 An out-of-bounds write vulnerability exists in firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Tenda Ax3 is an Ax1800 Gigabit port dual-band Wifi 6 wireless router from Tenda, China
| VAR-202203-0310 | CVE-2022-25547 | Tenda AX1806 fromSetSysTime function stack overflow vulnerability (CNVD-2022-23527) |
CVSS V2: 7.8 CVSS V3: 7.5 Severity: HIGH |
Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the time parameter. Tenda AX1806 is a WiFi6 wireless router from China Tenda company
| VAR-202203-0974 | CVE-2021-40060 | Huawei of EMUI and Magic UI Out-of-bounds write vulnerability in |
CVSS V2: 7.8 CVSS V3: 7.5 Severity: HIGH |
There is a heap-based buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerability may affect availability. Huawei of EMUI and Magic UI Exists in an out-of-bounds write vulnerability.Service operation interruption (DoS) It may be in a state
| VAR-202203-0968 | CVE-2021-40049 | plural Huawei Inappropriate Default Permission Vulnerability in Products |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
There is a permission control vulnerability in the PMS module. Successful exploitation of this vulnerability can lead to sensitive system information being obtained without authorization. Huawei of EMUI , HarmonyOS , Magic UI There is a vulnerability in improper default permissions.Information may be obtained