VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202107-1773 No CVE Bihaiwei L7 home gateway has command execution vulnerability CVSS V2: 7.1
CVSS V3: -
Severity: HIGH
Bihaiwei L7 home gateway is a home gateway launched by Beijing Bihaiwei Technology Co., Ltd. Bihaiwei L7 home gateway has a command execution vulnerability, which can be exploited by attackers to gain control of the server.
VAR-202107-1800 No CVE CTS Private Cloud-CDN Live Broadcast Acceleration Server Has Weak Password Vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Shenzhen Huashi Meida Information Technology Co., Ltd. is a smart hotel IT service provider. The Huashi Private Cloud-CDN live broadcast acceleration server has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1775 No CVE Unauthorized access vulnerability exists in ZXR10 6800 series CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
ZXR10 6800 series routers are a new generation of high-performance multi-service router products launched by ZTE Corporation. The ZXR10 6800 series has an unauthorized access vulnerability. Attackers can use this vulnerability to access the background by constructing a specific URL.
VAR-202107-1774 No CVE Zhongqin Communication Equipment Trading (Shanghai) Co., Ltd. NBG2105 has an unauthorized access vulnerability CVSS V2: 6.4
CVSS V3: -
Severity: MEDIUM
NBG2105 is a router of Zhongqin Communication Equipment Trading (Shanghai) Co., Ltd. Zhongqin Communication Equipment Trading (Shanghai) Co., Ltd. NBG2105 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1772 No CVE Ruijie Networks Co., Ltd. EG Easy Gateway has a command execution vulnerability CVSS V2: 7.1
CVSS V3: -
Severity: HIGH
Ruijie Networks Co., Ltd. is a professional network manufacturer with a full range of network equipment product lines and solutions including switches, routers, software, security firewalls, wireless products, and storage. Ruijie Networks Co., Ltd. EG Easy Gateway has a command execution vulnerability. Attackers can use this vulnerability to gain control of the server.
VAR-202107-1816 No CVE Vivo x27 has an information disclosure vulnerability CVSS V2: 4.7
CVSS V3: -
Severity: MEDIUM
Vivo x27 is a smart phone. Vivo x27 has an information disclosure vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1776 No CVE A variety of AC routers from Shenzhen Jixiang Tengda Technology Co., Ltd. have a denial of service vulnerability (CNVD-2021-41101) CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
Shenzhen Jixiang Tengda Technology Co., Ltd. is a high-tech enterprise integrating independent research and development, production and sales of network equipment. Many AC routers of Shenzhen Jixiang Tengda Technology Co., Ltd. have a denial of service vulnerability. Attackers can use the vulnerability to cause a denial of service attack.
VAR-202107-1903 No CVE Alibaba Smart APP has Janus vulnerability CVSS V2: 6.2
CVSS V3: -
Severity: MEDIUM
Ali Smart App is a mobile client made by Alibaba based on its Ali Smart Internet of Things platform. Alibaba Smart APP has a Janus vulnerability, which can be exploited by an attacker to gain control of the server.
VAR-202107-1797 No CVE Many AC routers of Shenzhen Jixiang Tengda Technology Co., Ltd. have a denial of service vulnerability (CNVD-2021-41102) CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
Shenzhen Jixiang Tengda Technology Co., Ltd. is a high-tech enterprise integrating independent research and development, production and sales of network equipment. Many AC routers of Shenzhen Jixiang Tengda Technology Co., Ltd. have a denial of service vulnerability. Attackers can use the vulnerability to cause a denial of service attack.
VAR-202107-1804 No CVE Many AC routers of Shenzhen Jixiang Tengda Technology Co., Ltd. have a denial of service vulnerability (CNVD-2021-41103) CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
Shenzhen Jixiang Tengda Technology Co., Ltd. is a high-tech enterprise integrating independent research and development, production and sales of network equipment. Many AC routers of Shenzhen Jixiang Tengda Technology Co., Ltd. have a denial of service vulnerability. Attackers can use the vulnerability to cause a denial of service attack.
VAR-202107-1805 No CVE A variety of AC routers from Shenzhen Jixiang Tengda Technology Co., Ltd. have a denial of service vulnerability CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
Shenzhen Jixiang Tengda Technology Co., Ltd. is a high-tech enterprise integrating independent research and development, production and sales of network equipment. Many AC routers of Shenzhen Jixiang Tengda Technology Co., Ltd. have a denial of service vulnerability. Attackers can use the vulnerability to cause a denial of service attack.
VAR-202107-1807 No CVE Many Tenda AC routers have stack buffer overflow vulnerabilities CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
Shenzhen Jixiang Tengda Technology Co., Ltd. is a high-tech enterprise integrating independent research and development, production and sales of network equipment. Many Tenda AC routers have stack buffer overflow vulnerabilities, which can be exploited by attackers to cause denial of service attacks.
VAR-202107-1798 No CVE Many AC routers of Shenzhen Jixiang Tengda Technology Co., Ltd. have a denial of service vulnerability (CNVD-2021-41100) CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
Shenzhen Jixiang Tengda Technology Co., Ltd. is a high-tech enterprise integrating independent research and development, production and sales of network equipment. Many AC routers of Shenzhen Jixiang Tengda Technology Co., Ltd. have a denial of service vulnerability. Attackers can use the vulnerability to cause a denial of service attack.
VAR-202107-1806 No CVE Binary vulnerabilities exist in many AC routers of Shenzhen Jixiang Tengda Technology Co., Ltd. CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
Shenzhen Jixiang Tengda Technology Co., Ltd. is a high-tech enterprise integrating independent research and development, production and sales of network equipment. Many AC routers of Shenzhen Jixiang Tengda Technology Co., Ltd. have binary vulnerabilities, which can be exploited by attackers to cause denial of service attacks.
VAR-202107-1799 No CVE Schneider Electric (China) Co., Ltd. PowerLogic ION8600 has an unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Schneider Electric (China) Co., Ltd. is a company whose main business includes power, industrial automation, infrastructure, energy efficiency, energy, building automation and security electronics, data centers and smart living spaces. Schneider Electric (China) Co., Ltd. PowerLogic ION8600 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-0298 CVE-2021-20507 IBM Jazz Foundation  and  IBM Engineering  Cross-site scripting vulnerabilities in products CVSS V2: 3.5
CVSS V3: 5.4
Severity: MEDIUM
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198235. Vendor exploits this vulnerability IBM X-Force ID: 198235 Is published as.Information may be obtained and information may be tampered with
VAR-202107-1803 No CVE Binary vulnerability exists in many AC routers of Shenzhen Jixiang Tengda Technology Co., Ltd. (CNVD-2021-41107) CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
Shenzhen Jixiang Tengda Technology Co., Ltd. is a high-tech enterprise integrating independent research and development, production and sales of network equipment. Many AC routers of Shenzhen Jixiang Tengda Technology Co., Ltd. have binary vulnerabilities, which can be exploited by attackers to cause denial of service attacks.
VAR-202107-1777 No CVE A variety of AC routers from Shenzhen Jixiang Tengda Technology Co., Ltd. have a denial of service vulnerability (CNVD-2021-41098) CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
Shenzhen Jixiang Tengda Technology Co., Ltd. is a high-tech enterprise integrating independent research and development, production and sales of network equipment. Many AC routers of Shenzhen Jixiang Tengda Technology Co., Ltd. have a denial of service vulnerability. Attackers can use the vulnerability to cause a denial of service attack.
VAR-202107-1906 No CVE New H3C SecPath ACG1000 has file inclusion vulnerabilities CVSS V2: 7.1
CVSS V3: -
Severity: HIGH
H3C SecPath ACG1000 is a new generation application control gateway. H3C SecPath ACG1000 has a file inclusion vulnerability, which can be exploited by attackers to gain control of the server.
VAR-202107-1795 No CVE Many AC routers of Shenzhen Jixiang Tengda Technology Co., Ltd. have a denial of service vulnerability (CNVD-2021-41097) CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
Shenzhen Jixiang Tengda Technology Co., Ltd. is a high-tech enterprise integrating independent research and development, production and sales of network equipment. Many AC routers of Shenzhen Jixiang Tengda Technology Co., Ltd. have a denial of service vulnerability. Attackers can use the vulnerability to cause a denial of service attack.