VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202107-1737 No CVE Unauthorized access vulnerability exists in Axis Communications AB P1355 CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
P1355 is a network camera of Axis Communications AB. Axis Communications AB P1355 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1746 No CVE Unauthorized access vulnerability exists in Axis Communications AB 210 CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Axis 210 is a network camera of Axis Communications AB. Axis Communications AB 210 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1747 No CVE 300M Giga Super High Power Wireless Router has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Sapido Technology Inc is a branded technology company invested by Taiwan Iron and Steel Group specifically for IoT technology. It specializes in the design and development of smart all-wireless security systems and hardware devices. The 300M Giga Super High Power Wireless Router has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1751 No CVE Panasonic Electric (China) Co., Ltd. WV-SW152 has an unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Matsushita Electric (China) Co., Ltd. was established in 1994 and is mainly responsible for the sales and after-sales service of home appliances, systems, environment, components and other commodities. Panasonic Electric (China) Co., Ltd. WV-SW152 has an unauthorized access vulnerability. Attackers can use this vulnerability to obtain sensitive information.
VAR-202107-1750 No CVE Panasonic Electric (China) Co., Ltd. WV-SF336 has an unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Matsushita Electric (China) Co., Ltd. was established in 1994 and is mainly responsible for the sales and after-sales service of home appliances, systems, environment, components and other commodities. Panasonic Electric (China) Co., Ltd. WV-SF336 has an unauthorized access vulnerability. Attackers can use this vulnerability to obtain sensitive information.
VAR-202107-1752 No CVE Panasonic Electric (China) Co., Ltd. WV-SW355 has an unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Matsushita Electric (China) Co., Ltd. was established in 1994 and is mainly responsible for the sales and after-sales service of home appliances, systems, environment, components and other commodities. Panasonic Electric (China) Co., Ltd. WV-SW355 has an unauthorized access vulnerability. Attackers can use this vulnerability to obtain sensitive information.
VAR-202107-1858 No CVE Panasonic Electric (China) Co., Ltd. WV-SP305 has an unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Matsushita Electric (China) Co., Ltd. was established in 1994 and is mainly responsible for the sales and after-sales service of home appliances, systems, environment, components and other commodities. Matsushita Electric (China) Co., Ltd. WV-SP305 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1741 No CVE Multiple BUFFALO routers have unauthorized access vulnerabilities CVSS V2: 6.4
CVSS V3: -
Severity: MEDIUM
BUFFALO is a Japanese manufacturer of computer peripheral products. Many BUFFALO routers have unauthorized access vulnerabilities, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1749 No CVE Phicomm router K3C has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Phicomm Data Communication Technology Co., Ltd. was established in 2009 and is a technologically innovative enterprise that provides users with smart products and cloud services in the field of smart homes. Phicomm router K3C has a weak password vulnerability. Attackers can use weak passwords to log in to the background to obtain sensitive information.
VAR-202107-1738 No CVE Unauthorized access vulnerability exists in Axis Communications AB 211 CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Axis 211 is a network camera of Axis Communications AB. Axis Communications AB 211 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1743 No CVE Unauthorized access vulnerability exists in Axis Communications AB 211M CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Axis 211M is a network camera of Axis Communications AB. Axis Communications AB 211M has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1862 No CVE HP LaserJet 100 colorMFP M175nw and HP Color LaserJet MFP M183fw have unauthorized access vulnerabilities CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Hewlett-Packard Trading (Shanghai) Co., Ltd. was established in 1999. Its business scope includes: computer software and hardware equipment, printing equipment, imaging equipment, communication equipment, electronic products and related parts and components of the above products. HP LaserJet 100 colorMFP M175nw and HP Color LaserJet MFP M183fw have unauthorized access vulnerabilities, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1748 No CVE Huawei Technologies Co., Ltd. HG630 V2 Home Gateway has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Founded in 1987, Huawei Technologies Co., Ltd. is the world's leading provider of ICT (information and communications) infrastructure and smart terminals. Huawei Technologies Co., Ltd. HG630 V2 Home Gateway has a weak password vulnerability. Attackers can use the vulnerability to obtain sensitive information.
VAR-202107-1855 No CVE Panasonic Electric (China) Co., Ltd. WV-SPN310 and WV-SPN310A have unauthorized access vulnerabilities CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Matsushita Electric (China) Co., Ltd. was established in 1994 and is mainly responsible for the sales and after-sales service of home appliances, systems, environment, components and other commodities. Matsushita Electric (China) Co., Ltd. WV-SPN310 and WV-SPN310A have unauthorized access vulnerabilities, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1754 No CVE Panasonic Electric (China) Co., Ltd. WV-SW458 has an unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Matsushita Electric (China) Co., Ltd. was established in 1994 and is mainly responsible for the sales and after-sales service of home appliances, systems, environment, components and other commodities. Panasonic Electric (China) Co., Ltd. WV-SW458 has an unauthorized access vulnerability. Attackers can use this vulnerability to obtain sensitive information.
VAR-202107-1739 No CVE Unauthorized access vulnerability exists in Axis Communications AB M1014 CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
M1014 is a network camera of Axis Communications AB. Axis Communications AB M1014 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1760 No CVE Anbottom Deep Security Gateway has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Beijing Anbotong Technology Co., Ltd. (abbreviated as “Anbotong”), started in 2011, with the concept of "seeing security and experiencing value" as the core, is a dedicated core system product and security service provider for visual network security. Anbottom Deep Security Gateway has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-0025 CVE-2020-14032 ASRock 4x4 BOX-R1000  Vulnerability in privilege management in CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
ASRock 4x4 BOX-R1000 before BIOS P1.40 allows privilege escalation via code execution in the SMM. ASRock 4x4 BOX-R1000 Exists in a permission management vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202107-0200 CVE-2020-20741 Beckhoff Automation GmbH & Co. KG CX9020  Firmware vulnerabilities CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
Incorrect Access Control in Beckhoff Automation GmbH & Co. KG CX9020 with firmware version CX9020_CB3011_WEC7_HPS_v602_TC31_B4016.6 allows remote attackers to bypass authentication via the "CE Remote Display Tool" as it does not close the incoming connection on the Windows CE side if the credentials are incorrect. KG CX9020 There are unspecified vulnerabilities in the firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202107-1757 No CVE ZTE Corporation ZXV10 I508C has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
ZXV10 I508C is a wireless router of ZTE Corporation. ZTE Corporation ZXV10 I508C has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.