VARIoT IoT vulnerabilities database

VAR-202108-2472 | No CVE | Command execution vulnerability exists in Xiaodu routing audio and video version |
CVSS V2: 8.3 CVSS V3: - Severity: HIGH |
Xiaodu Router is a smart router product launched by Baidu, which can transmit cloud data at will and supports remote download of audio and video resources.
There is a command execution vulnerability in the Xiaodu routing audio and video version, which can be exploited by attackers to gain server control rights.
VAR-202108-2475 | CVE-2021-38784 | Allwinner R818 SoC Android Q SDK In NULL Pointer dereference vulnerability |
CVSS V2: 7.8 CVSS V3: 7.5 Severity: HIGH |
There is a NULL pointer dereference in the syscall open_exec function of Allwinner R818 SoC Android Q SDK V1.0 that could executable a malicious file to cause a system crash. R818 is a quad-core smart voice chip with screen.
Zhuhai Allwinner Technology Co., Ltd. R818 has a binary vulnerability that can be exploited by attackers to cause a denial of service
VAR-202108-2474 | No CVE | Toshiba (China) Co., Ltd. network camera has an unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Toshiba (China) Co., Ltd. is a company mainly engaged in Toshiba's four major business areas, including digital products, electronic components, social infrastructure, and household appliances.
Toshiba (China) Co., Ltd. network cameras have an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2316 | No CVE | Xiaodu routing has unauthorized access vulnerabilities |
CVSS V2: 3.3 CVSS V3: - Severity: LOW |
Xiaodu Router is a smart router product launched by Baidu, which can transmit cloud data at will and supports remote download of audio and video resources.
Xiaodu routing has unauthorized access vulnerabilities, and attackers can use vulnerabilities to obtain sensitive information.
VAR-202108-1844 | CVE-2021-36277 | Dell Command Update and Alienware Update Digital Signature Verification Vulnerability in |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
Dell Command | Update, Dell Update, and Alienware Update versions before 4.3 contains an Improper Verification of Cryptographic Signature Vulnerability. A local authenticated malicious user may exploit this vulnerability by executing arbitrary code on the system
VAR-202108-2319 | No CVE | Samsung (China) Investment Co., Ltd. K4250RX has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Samsung (China) Investment Co., Ltd. is the headquarters of Samsung Group in China. As of the end of 2008, 20 of Samsung's more than 30 companies have invested in China, including Samsung Electronics, Samsung SDI, Samsung SDS, and Samsung Electro-Mechanics.
SAMSUNG K4250RX has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2350 | No CVE | GW Security NVR series network camera NVR has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
The NVR series is a network camera of GW Security.
The GW Security NVR series network camera NVR has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2351 | No CVE | Kyocera Corporation ECOSYS M5520cdn has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
ECOSYS M5520cdn is a printer of Kyocera Corporation.
Kyocera Corporation’s ECOSYS M5520cdn has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2352 | No CVE | Kyocera Corporation TASKalfa 2552ci has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
TASKalfa 2552ci is a printer of Kyocera Corporation.
Kyocera Corporation TASKalfa 2552ci has an unauthorized access vulnerability. Attackers can use the vulnerability to obtain sensitive information.
VAR-202108-2353 | No CVE | Samsung Galaxy S10 has an information disclosure vulnerability |
CVSS V2: 2.1 CVSS V3: - Severity: LOW |
Samsung Galaxy S10 is the flagship model of a new generation of smartphones launched by South Korea's Samsung. It is equipped with Qualcomm Snapdragon 855 processor and has a 6.1-inch screen.
Samsung Galaxy S10 has an information disclosure vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2354 | No CVE | Information disclosure vulnerability exists in Huawei M6 |
CVSS V2: 2.1 CVSS V3: - Severity: LOW |
Huawei M6 is equipped with the flagship Kirin 980 processor and supports 2560*1600 2K-level high-definition screens.
Huawei M6 has an information disclosure vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2355 | No CVE | Samsung (China) Investment Co., Ltd. M2070 Series has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Samsung (China) Investment Co., Ltd. is the headquarters of Samsung Group in China. As of the end of 2008, 20 of Samsung's more than 30 companies have invested in China, including Samsung Electronics, Samsung SDI, Samsung SDS, and Samsung Electro-Mechanics.
Samsung (China) Investment Co., Ltd. M2070 Series has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2356 | No CVE | Samsung (China) Investment Co., Ltd. K3250NR has an unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Samsung (China) Investment Co., Ltd. is the headquarters of Samsung Group in China. As of the end of 2008, 20 of Samsung's more than 30 companies have invested in China, including Samsung Electronics, Samsung SDI, Samsung SDS, and Samsung Electro-Mechanics.
Samsung (China) Investment Co., Ltd. K3250NR has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2357 | No CVE | Samsung (China) Investment Co., Ltd. K7400LX has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Samsung (China) Investment Co., Ltd. is the headquarters of Samsung Group in China. As of the end of 2008, 20 of Samsung's more than 30 companies have invested in China, including Samsung Electronics, Samsung SDI, Samsung SDS, and Samsung Electro-Mechanics.
Samsung (China) Investment Co., Ltd. K7400LX has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2358 | No CVE | Samsung (China) Investment Co., Ltd. K401LX has an unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Samsung (China) Investment Co., Ltd. is the headquarters of Samsung Group in China. As of the end of 2008, 20 of Samsung's more than 30 companies have invested in China, including Samsung Electronics, Samsung SDI, Samsung SDS, and Samsung Electro-Mechanics.
Samsung (China) Investment Co., Ltd. K401LX has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2558 | No CVE | Wuxi Chengan Information Technology Co., Ltd. citysec Reporter has an information disclosure vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
The business scope of Wuxi Chengan Information Technology Co., Ltd. includes: research and development of communication technology, computer software, Internet of Things technology, technical services, etc.
Wuxi Chengan Information Technology Co., Ltd. citysec Reporter has an information disclosure vulnerability. Attackers can use the vulnerability to obtain sensitive information.
VAR-202108-2430 | No CVE | Samsung (China) Investment Co., Ltd. K4305LX has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Samsung (China) Investment Co., Ltd. is the headquarters of Samsung Group in China. As of the end of 2008, 20 of Samsung's more than 30 companies have invested in China, including Samsung Electronics, Samsung SDI, Samsung SDS, and Samsung Electro-Mechanics.
Samsung (China) Investment Co., Ltd. K4305LX has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2431 | No CVE | Samsung (China) Investment Co., Ltd. K4350LX has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Samsung (China) Investment Co., Ltd. is the headquarters of Samsung Group in China. As of the end of 2008, 20 of Samsung's more than 30 companies have invested in China, including Samsung Electronics, Samsung SDI, Samsung SDS, and Samsung Electro-Mechanics.
Samsung (China) Investment Co., Ltd. K4350LX has an unauthorized access vulnerability. Attackers can use the vulnerability to obtain sensitive information.
VAR-202108-2432 | No CVE | Samsung (China) Investment Co., Ltd. M2085FW has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Samsung (China) Investment Co., Ltd. is the headquarters of Samsung Group in China. As of the end of 2008, 20 of Samsung's more than 30 companies have invested in China, including Samsung Electronics, Samsung SDI, Samsung SDS, and Samsung Electro-Mechanics.
Samsung (China) Investment Co., Ltd. M2085FW has an unauthorized access vulnerability. Attackers can use the vulnerability to obtain sensitive information.
VAR-202108-2433 | No CVE | Epson (China) Co., Ltd. L6190 Series has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Epson (China) Co., Ltd. was established in 1998 and is headquartered in Beijing. It is responsible for overseeing Epson's investment and business development in China.
Epson (China) Co., Ltd. L6190 Series has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.