VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202108-2472 No CVE Command execution vulnerability exists in Xiaodu routing audio and video version CVSS V2: 8.3
CVSS V3: -
Severity: HIGH
Xiaodu Router is a smart router product launched by Baidu, which can transmit cloud data at will and supports remote download of audio and video resources. There is a command execution vulnerability in the Xiaodu routing audio and video version, which can be exploited by attackers to gain server control rights.
VAR-202108-2475 CVE-2021-38784 Allwinner R818 SoC Android Q SDK  In  NULL  Pointer dereference vulnerability CVSS V2: 7.8
CVSS V3: 7.5
Severity: HIGH
There is a NULL pointer dereference in the syscall open_exec function of Allwinner R818 SoC Android Q SDK V1.0 that could executable a malicious file to cause a system crash. R818 is a quad-core smart voice chip with screen. Zhuhai Allwinner Technology Co., Ltd. R818 has a binary vulnerability that can be exploited by attackers to cause a denial of service
VAR-202108-2474 No CVE Toshiba (China) Co., Ltd. network camera has an unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Toshiba (China) Co., Ltd. is a company mainly engaged in Toshiba's four major business areas, including digital products, electronic components, social infrastructure, and household appliances. Toshiba (China) Co., Ltd. network cameras have an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2316 No CVE Xiaodu routing has unauthorized access vulnerabilities CVSS V2: 3.3
CVSS V3: -
Severity: LOW
Xiaodu Router is a smart router product launched by Baidu, which can transmit cloud data at will and supports remote download of audio and video resources. Xiaodu routing has unauthorized access vulnerabilities, and attackers can use vulnerabilities to obtain sensitive information.
VAR-202108-1844 CVE-2021-36277 Dell Command Update  and  Alienware Update  Digital Signature Verification Vulnerability in CVSS V2: 7.2
CVSS V3: 7.8
Severity: HIGH
Dell Command | Update, Dell Update, and Alienware Update versions before 4.3 contains an Improper Verification of Cryptographic Signature Vulnerability. A local authenticated malicious user may exploit this vulnerability by executing arbitrary code on the system
VAR-202108-2319 No CVE Samsung (China) Investment Co., Ltd. K4250RX has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Samsung (China) Investment Co., Ltd. is the headquarters of Samsung Group in China. As of the end of 2008, 20 of Samsung's more than 30 companies have invested in China, including Samsung Electronics, Samsung SDI, Samsung SDS, and Samsung Electro-Mechanics. SAMSUNG K4250RX has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2350 No CVE GW Security NVR series network camera NVR has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
The NVR series is a network camera of GW Security. The GW Security NVR series network camera NVR has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2351 No CVE Kyocera Corporation ECOSYS M5520cdn has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
ECOSYS M5520cdn is a printer of Kyocera Corporation. Kyocera Corporation’s ECOSYS M5520cdn has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2352 No CVE Kyocera Corporation TASKalfa 2552ci has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
TASKalfa 2552ci is a printer of Kyocera Corporation. Kyocera Corporation TASKalfa 2552ci has an unauthorized access vulnerability. Attackers can use the vulnerability to obtain sensitive information.
VAR-202108-2353 No CVE Samsung Galaxy S10 has an information disclosure vulnerability CVSS V2: 2.1
CVSS V3: -
Severity: LOW
Samsung Galaxy S10 is the flagship model of a new generation of smartphones launched by South Korea's Samsung. It is equipped with Qualcomm Snapdragon 855 processor and has a 6.1-inch screen. Samsung Galaxy S10 has an information disclosure vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2354 No CVE Information disclosure vulnerability exists in Huawei M6 CVSS V2: 2.1
CVSS V3: -
Severity: LOW
Huawei M6 is equipped with the flagship Kirin 980 processor and supports 2560*1600 2K-level high-definition screens. Huawei M6 has an information disclosure vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2355 No CVE Samsung (China) Investment Co., Ltd. M2070 Series has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Samsung (China) Investment Co., Ltd. is the headquarters of Samsung Group in China. As of the end of 2008, 20 of Samsung's more than 30 companies have invested in China, including Samsung Electronics, Samsung SDI, Samsung SDS, and Samsung Electro-Mechanics. Samsung (China) Investment Co., Ltd. M2070 Series has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2356 No CVE Samsung (China) Investment Co., Ltd. K3250NR has an unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Samsung (China) Investment Co., Ltd. is the headquarters of Samsung Group in China. As of the end of 2008, 20 of Samsung's more than 30 companies have invested in China, including Samsung Electronics, Samsung SDI, Samsung SDS, and Samsung Electro-Mechanics. Samsung (China) Investment Co., Ltd. K3250NR has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2357 No CVE Samsung (China) Investment Co., Ltd. K7400LX has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Samsung (China) Investment Co., Ltd. is the headquarters of Samsung Group in China. As of the end of 2008, 20 of Samsung's more than 30 companies have invested in China, including Samsung Electronics, Samsung SDI, Samsung SDS, and Samsung Electro-Mechanics. Samsung (China) Investment Co., Ltd. K7400LX has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2358 No CVE Samsung (China) Investment Co., Ltd. K401LX has an unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Samsung (China) Investment Co., Ltd. is the headquarters of Samsung Group in China. As of the end of 2008, 20 of Samsung's more than 30 companies have invested in China, including Samsung Electronics, Samsung SDI, Samsung SDS, and Samsung Electro-Mechanics. Samsung (China) Investment Co., Ltd. K401LX has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2558 No CVE Wuxi Chengan Information Technology Co., Ltd. citysec Reporter has an information disclosure vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
The business scope of Wuxi Chengan Information Technology Co., Ltd. includes: research and development of communication technology, computer software, Internet of Things technology, technical services, etc. Wuxi Chengan Information Technology Co., Ltd. citysec Reporter has an information disclosure vulnerability. Attackers can use the vulnerability to obtain sensitive information.
VAR-202108-2430 No CVE Samsung (China) Investment Co., Ltd. K4305LX has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Samsung (China) Investment Co., Ltd. is the headquarters of Samsung Group in China. As of the end of 2008, 20 of Samsung's more than 30 companies have invested in China, including Samsung Electronics, Samsung SDI, Samsung SDS, and Samsung Electro-Mechanics. Samsung (China) Investment Co., Ltd. K4305LX has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2431 No CVE Samsung (China) Investment Co., Ltd. K4350LX has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Samsung (China) Investment Co., Ltd. is the headquarters of Samsung Group in China. As of the end of 2008, 20 of Samsung's more than 30 companies have invested in China, including Samsung Electronics, Samsung SDI, Samsung SDS, and Samsung Electro-Mechanics. Samsung (China) Investment Co., Ltd. K4350LX has an unauthorized access vulnerability. Attackers can use the vulnerability to obtain sensitive information.
VAR-202108-2432 No CVE Samsung (China) Investment Co., Ltd. M2085FW has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Samsung (China) Investment Co., Ltd. is the headquarters of Samsung Group in China. As of the end of 2008, 20 of Samsung's more than 30 companies have invested in China, including Samsung Electronics, Samsung SDI, Samsung SDS, and Samsung Electro-Mechanics. Samsung (China) Investment Co., Ltd. M2085FW has an unauthorized access vulnerability. Attackers can use the vulnerability to obtain sensitive information.
VAR-202108-2433 No CVE Epson (China) Co., Ltd. L6190 Series has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Epson (China) Co., Ltd. was established in 1998 and is headquartered in Beijing. It is responsible for overseeing Epson's investment and business development in China. Epson (China) Co., Ltd. L6190 Series has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.