VARIoT IoT vulnerabilities database

VAR-202108-2333 | No CVE | Anbottom Deep Security Gateway has file download vulnerabilities |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Beijing Anbotong Technology Co., Ltd. is a dedicated core system product and security service provider for visual network security.
Ambton Deep Security Gateway has a file download vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1711 | No CVE | Rascomda Technology Development Co., Ltd. security router has an arbitrary file download vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Raisecomda Technology Development Co., Ltd. focuses on the field of optical fiber broadband access, and is committed to the integration of optical fiber technology, Ethernet technology and broadband access technology.
The security router of Rascomda Technology Development Co., Ltd. has an arbitrary file download vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1710 | No CVE | Any file download vulnerability exists in the multi-service security gateway of Shanghai Huayi Technology Group Co., Ltd. |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Shanghai Huayi Technology Group Co., Ltd. is a company mainly engaged in the research and development, manufacturing of test benches in the field of automotive powertrain and the provision of related technical services.
An arbitrary file download vulnerability exists in the multi-service security gateway of Shanghai Huayi Technology Group Co., Ltd., which can be exploited by attackers to obtain sensitive information.
VAR-202107-1713 | No CVE | Hikvision security access gateway has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Hangzhou Hikvision Digital Technology Co., Ltd. is a leading provider of security products and industry solutions.
Hikvision security access gateway has weak password vulnerability. Attackers can use this vulnerability to log in to the background to obtain sensitive information.
VAR-202107-1712 | No CVE | Any file download vulnerability exists in Hikvision's secure access gateway |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Hangzhou Hikvision Digital Technology Co., Ltd. is a leading provider of security products and industry solutions.
The Hikvision secure access gateway has an arbitrary file download vulnerability. Attackers can use this vulnerability to obtain sensitive information.
VAR-202107-1709 | No CVE | Any file download vulnerability exists in the next-generation firewall security gateway of Feiyuxing |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Chengdu Feiyuxing Technology Co., Ltd. is one of the few local enterprises in the industry with independent intellectual property rights and independent research and development capabilities. It is a high-tech enterprise focusing on product innovation and research in the data communication industry and the Internet of Things industry.
There is an arbitrary file download vulnerability in the Feiyuxing next-generation firewall security gateway, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1714 | No CVE | Xingwang Smart SVG6000 series voice gateways have weak password vulnerabilities |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
As the core business unit of StarNet Ruijie for smart communications, StarNet Wisdom is a leading provider of converged communication solutions in China.
Starnet Smart SVG6000 series voice gateways have weak password vulnerabilities. The attacker uses a weak password to log in to the background to obtain sensitive information.
VAR-202107-1878 | No CVE | Unauthorized access vulnerability exists in Cisco IP Phone CP-8865 |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Cisco IP Phone CP-8865 is an enterprise-class IP phone.
Cisco IP Phone CP-8865 has an unauthorized access vulnerability. Attackers can use vulnerabilities to obtain sensitive information.
VAR-202107-1880 | No CVE | Unauthorized access vulnerability exists in AXIS M7014 Video Encoder |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS M7014 Video Encoder has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1876 | No CVE | AXIS P3344 Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS P3344 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1877 | No CVE | AXIS P1353 Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS P1353 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1874 | No CVE | AXIS M3025 Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS M3025 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1883 | No CVE | Unauthorized access vulnerability exists in AXIS 241S Video Server |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS 241S Video Server has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1873 | No CVE | AXIS M3113 Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS M3113 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1884 | No CVE | Unauthorized access vulnerability exists in AXIS 241Q Video Server |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS 241Q Video Server has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1872 | No CVE | AXIS M5014 Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS M5014 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1715 | CVE-2025-34044 | WIFISKY 7-layer flow control router has command execution vulnerabilities |
CVSS V2: 7.1 CVSS V3: - Severity: Critical |
A remote command injection vulnerability exists in the confirm.php interface of the WIFISKY 7-layer Flow Control Router via a specially-crafted HTTP GET request to the t parameter. Insufficient input validation allows unauthenticated attackers to execute arbitrary OS commands. Shenzhen Airspace Technology Co., Ltd. ("Airspace Technology" for short) is a network communication equipment supplier rooted in Shenzhen and radiating the world. An attacker can use this vulnerability to gain control of the server
VAR-202107-1716 | No CVE | Huawei HG659 has an arbitrary file reading vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Huawei HG659 is a home gateway.
Huawei HG659 has arbitrary file reading vulnerabilities. Attackers can use the vulnerabilities to obtain sensitive information.
VAR-202107-0947 | CVE-2021-29298 | Emerson GE Automation Proficy Machine Edition Input verification vulnerability in |
CVSS V2: 2.6 CVSS V3: 5.3 Severity: MEDIUM |
Improper Input Validation in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service and application crash via crafted traffic from a Man-in-the-Middle (MITM) attack to the component "FrameworX.exe"in the module "fxVPStatcTcp.dll"
VAR-202107-1871 | No CVE | AXIS M3114 Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS M3114 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.