VARIoT IoT vulnerabilities database

VAR-202107-0417 | CVE-2020-5351 | Dell EMC Data Protection Advisor Security hole |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
Dell EMC Data Protection Advisor versions 6.4, 6.5 and 18.1 contain an undocumented account with limited privileges that is protected with a hard-coded password. A remote unauthenticated malicious user with the knowledge of the hard-coded password may login to the system and gain read-only privileges. The product supports functions such as data backup, data recovery, and data replication management
VAR-202107-0219 | CVE-2020-26180 | Dell EMC Isilon OneFS and EMC PowerScale Permission Licensing and Access Control Issue Vulnerability |
CVSS V2: 6.5 CVSS V3: 8.8 Severity: HIGH |
Dell EMC Isilon OneFS supported versions 8.1 and later and Dell EMC PowerScale OneFS supported version 9.0.0 contain an access issue with the remotesupport user account. A remote malicious user with low privileges may gain access to data stored on the /ifs directory through most protocols. DELL Dell EMC Isilon OneFS and EMC PowerScale are a set of scale-out storage systems suitable for unstructured data from Dell (DELL)
VAR-202107-1725 | No CVE | D-Link DIR-818LW has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
D-Link DIR-818LW is a wireless router.
D-Link DIR-818LW has a weak password vulnerability. Attackers can use weak passwords to log in to the background to obtain sensitive information.
VAR-202107-1729 | No CVE | Wisdom technology enterprise-level flow control cloud router has weak password vulnerability |
CVSS V2: 4.0 CVSS V3: - Severity: MEDIUM |
Beijing Zhimin Technology Development Co., Ltd. is a high-tech enterprise specializing in the research and development, production, sales, leasing and service of security inspection, anti-terrorism, police, fire rescue and EOD equipment.
MinTech's enterprise-level flow control cloud router has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1726 | No CVE | D-Link DIR-600M has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
D-Link DIR-600M is a wireless router.
D-Link DIR-600M has weak password vulnerability. Attackers use this vulnerability to log in to the background to obtain sensitive information.
VAR-202107-1727 | No CVE | Ruijie Networks RG-EW1200G has a command execution vulnerability |
CVSS V2: 7.1 CVSS V3: - Severity: HIGH |
RG-EW1200G is a dual-band dual-gigabit wireless router.
Ruijie Networks RG-EW1200G has a command execution vulnerability. An attacker can use this vulnerability to gain control of the website server.
VAR-202107-1723 | No CVE | TOTOLINK T10 router has command execution vulnerability (CNVD-2021-44929) |
CVSS V2: 8.3 CVSS V3: - Severity: HIGH |
TOTOLINK is a brand owned by Zeon Electronics (Shenzhen) Co., Ltd. Founded in 1999, it is a Hong Kong-listed high-tech foreign company (stock code: HK.8287) and one of the world's leading network equipment suppliers.
The TOTOLINK T10 router has a command execution vulnerability. Attackers can use this vulnerability to execute arbitrary commands.
VAR-202107-1735 | No CVE | TOTOLINK T10 router has command execution vulnerability (CNVD-2021-43462) |
CVSS V2: 8.3 CVSS V3: - Severity: HIGH |
TOTOLINK is a brand owned by Zeon Electronics (Shenzhen) Co., Ltd. Founded in 1999, it is a Hong Kong-listed high-tech foreign company (stock code: HK.8287) and one of the world's leading network equipment suppliers.
TOTOLINK T10 router has a command execution vulnerability. Attackers can use this vulnerability to execute arbitrary commands.
VAR-202107-1910 | No CVE | Hysine Webtalk system has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Hysine (Hexin Control) is the world's leading manufacturer of BACnet control systems.
The Hysine Webtalk system has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1724 | No CVE | TOTOLINK T10 router has command execution vulnerability (CNVD-2021-44930) |
CVSS V2: 8.3 CVSS V3: - Severity: HIGH |
TOTOLINK is a brand owned by Zeon Electronics (Shenzhen) Co., Ltd. Founded in 1999, it is a Hong Kong-listed high-tech foreign company (stock code: HK.8287) and one of the world's leading network equipment suppliers.
The TOTOLINK T10 router has a command execution vulnerability. Attackers can use this vulnerability to execute arbitrary commands.
VAR-202107-1728 | No CVE | A weak password vulnerability exists in the enterprise-level flow control cloud router of Fengwang Interconnection |
CVSS V2: 4.0 CVSS V3: - Severity: MEDIUM |
Chengdu Zhifeng Technology Co., Ltd. was established in October 2016. It is an emerging high-tech company integrating R&D, production and sales.
The enterprise-level flow control cloud router of BeeNet has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1733 | No CVE | Command execution vulnerability exists in TOTOLINK T10 router (CNVD-2021-44931) |
CVSS V2: 8.3 CVSS V3: - Severity: HIGH |
TOTOLINK is a brand owned by Zeon Electronics (Shenzhen) Co., Ltd. Founded in 1999, it is a Hong Kong-listed high-tech foreign company (stock code: HK.8287) and one of the world's leading network equipment suppliers.
TOTOLINK T10 router has a command execution vulnerability. Attackers can use this vulnerability to execute arbitrary commands.
VAR-202107-1734 | No CVE | TOTOLINK T10 router has a command execution vulnerability (CNVD-2021-43461) |
CVSS V2: 8.3 CVSS V3: - Severity: HIGH |
TOTOLINK is a brand owned by Zeon Electronics (Shenzhen) Co., Ltd. Founded in 1999, it is a Hong Kong-listed high-tech foreign company (stock code: HK.8287) and one of the world's leading network equipment suppliers.
TOTOLINK T10 router has a command execution vulnerability. Attackers can use this vulnerability to execute arbitrary commands.
VAR-202107-1731 | No CVE | D_Link DIR-850L has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
DIR-850L is a wireless AC1200 dual-band gigabit cloud router.
D_Link DIR-850L has a weak password vulnerability, attackers can use the vulnerability to obtain sensitive information
VAR-202107-1730 | No CVE | Suzhou Keda Technology Co., Ltd. MSS streaming media server has logic flaws and vulnerabilities |
CVSS V2: 6.4 CVSS V3: - Severity: MEDIUM |
Suzhou Keda Technology Co., Ltd. is a leading provider of video and security products and solutions. It is committed to helping various government and corporate customers improve communication and management efficiency with video conferencing, video surveillance and rich video application solutions.
The MSS streaming media server of Suzhou Keda Technology Co., Ltd. has a logical flaw, and an attacker can use the flaw to obtain sensitive information.
VAR-202107-1732 | No CVE | Command execution vulnerability exists in TOTOLINK T10 router (CNVD-2021-43463) |
CVSS V2: 8.3 CVSS V3: - Severity: HIGH |
TOTOLINK is a brand owned by Zeon Electronics (Shenzhen) Co., Ltd. Founded in 1999, it is a Hong Kong-listed high-tech foreign company (stock code: HK.8287) and one of the world's leading network equipment suppliers.
TOTOLINK T10 router has a command execution vulnerability. Attackers can use this vulnerability to execute arbitrary commands.
VAR-202107-1852 | No CVE | Panasonic Corporation (China) Co., Ltd. multiple models of network cameras have unauthorized access vulnerabilities |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Matsushita Electric (China) was established in 1994 and is mainly responsible for the sales and after-sales service of home appliances, systems, environment, components and other products.
Multiple network cameras of Panasonic Electric (China) Co., Ltd. have unauthorized access vulnerabilities. Attackers can use the vulnerabilities to obtain sensitive information.
VAR-202107-1854 | No CVE | BRIC Communication Technology Co., Ltd. VD-130Ae camera has a weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Brickcom Corporation (Brickcom Corporation) is composed of a research and development team with rich experience in the surveillance industry, and develops digital surveillance products with advanced technology. Including millions of video network cameras, wireless network cameras, video servers, 3G video transmission (NVR) embedded network hard disk video recorders, CMS client platform systems, etc.
The VD-130Ae camera of BRICS Communication Technology Co., Ltd. has a weak password vulnerability. Attackers can use the vulnerability to obtain sensitive information.
VAR-202107-1855 | No CVE | Panasonic Electric (China) Co., Ltd. WV-SPN310 and WV-SPN310A have unauthorized access vulnerabilities |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Matsushita Electric (China) Co., Ltd. was established in 1994 and is mainly responsible for the sales and after-sales service of home appliances, systems, environment, components and other commodities.
Matsushita Electric (China) Co., Ltd. WV-SPN310 and WV-SPN310A have unauthorized access vulnerabilities, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1853 | No CVE | Brickcom-MD-300Np-360P has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Brickcom Corporation (Brickcom Corporation) is composed of a research and development team with rich experience in the surveillance industry, and develops digital surveillance products with advanced technology. Including millions of video network cameras, wireless network cameras, video servers, 3G video transmission (NVR) embedded network hard disk video recorders, CMS client platform systems, etc.
Brickcom-MD-300Np-360P has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.