VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202106-2011 No CVE NETGEAR DGN1000 has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
NETGEAR DGN1000 is a wireless router. NETGEAR DGN1000 has a weak password vulnerability. The attacker uses a weak password to log in to the background to obtain sensitive information.
VAR-202106-2007 No CVE Suzhou Hamming Technology Co., Ltd. Howay SW-26242 has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Howay SW-26242 is a full Gigabit managed POE switch. Suzhou Hamming Technology Co., Ltd. Howay SW-26242 has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2010 No CVE NETGEAR DGN2200v3 has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
NETGEAR DGN2200v3 is a wireless router. NETGEAR DGN2200v3 has a weak password vulnerability. The attacker uses a weak password to log in to the background to obtain sensitive information.
VAR-202106-2012 No CVE Airspace technology WIFISKY 7-layer flow control router has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Shenzhen Airspace Technology Co., Ltd. is a network communication equipment supplier, dedicated to the research and development of network communication equipment. Airspace technology WIFISKY 7-layer flow control router has a weak password vulnerability. The attacker uses a weak password to log in to the background to obtain sensitive information.
VAR-202106-2017 No CVE NETGEAR WPN824 has an information disclosure vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
NETGEAR WPN824 is a wireless broadband router. NETGEAR WPN824 has an information disclosure vulnerability. Attackers can use vulnerabilities to obtain sensitive information.
VAR-202106-2018 No CVE NETGEAR WNR3500 has an information disclosure vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
NETGEAR WNR3500 is a wireless router. NETGEAR WNR3500 has an information disclosure vulnerability. Attackers can use vulnerabilities to obtain sensitive information.
VAR-202106-2008 No CVE Shenzhen Wanwang Broadcom Technology Co., Ltd. 26G-2F-MANAGED has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Committed to the development and application of network communication products and IoT security management and control platforms, it is a next-generation weak current intelligent network solution and IoT security solution manufacturer. Shenzhen Wanwang Broadcom Technology Co., Ltd. 26G-2F-MANAGED has a weak password vulnerability. The attacker uses a weak password to log in to the background to obtain sensitive information.
VAR-202106-2016 No CVE NETGEAR DGN2200M has an information disclosure vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
NETGEAR DGN2200M is a wireless router. NETGEAR DGN2200M has an information disclosure vulnerability. Attackers can use this vulnerability to obtain sensitive information.
VAR-202106-2014 No CVE FLIR-AX8 has an arbitrary file download vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Teledyne FLIR focuses on the design, development, production, marketing and promotion of professional technologies for enhancing situational awareness. FLIR-AX8 has an arbitrary file download vulnerability. Attackers can use vulnerabilities to download related system configuration files.
VAR-202106-2021 No CVE D-Link DIR-809 has a denial of service vulnerability (CNVD-2021-37564) CVSS V2: 4.9
CVSS V3: -
Severity: MEDIUM
D-Link DIR-809 is a wireless router using RTOS. D-Link DIR-809 has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service.
VAR-202106-2019 No CVE Feiyuxing home smart router has logic flaw vulnerability (CNVD-2021-37568) CVSS V2: 6.4
CVSS V3: -
Severity: MEDIUM
Chengdu Feiyuxing Technology Co., Ltd. serves enterprise, commercial and home users, providing intelligent and easy-to-use network communication management equipment and innovative technology value-added services. Feiyuxing home intelligent routing has logic flaws and loopholes. Attackers can use this vulnerability to directly log in to the background of the system and operate to access any page in the background.
VAR-202106-2022 No CVE D-Link DIR-809 has a denial of service vulnerability (CNVD-2021-37559) CVSS V2: 4.9
CVSS V3: -
Severity: MEDIUM
D-Link DIR-809 is a wireless router using RTOS. D-Link DIR-809 has a denial of service vulnerability. An attacker can use this vulnerability to cause a denial of service.
VAR-202106-2013 No CVE D-Link DIR-809 has a binary vulnerability CVSS V2: 4.9
CVSS V3: -
Severity: MEDIUM
D-Link DIR-809 is a wireless router using RTOS. D-Link DIR-809 has a binary vulnerability, which can be exploited by an attacker to cause a denial of service.
VAR-202106-2020 No CVE Enterprise-level flow control cloud routers have logic flaws and vulnerabilities CVSS V2: 6.4
CVSS V3: -
Severity: MEDIUM
Chengdu Zhifeng Technology Co., Ltd. was established in October 2016. It is an emerging high-tech company integrating R&D, production and sales. The enterprise-level flow control cloud router has a logic flaw vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2023 No CVE D-Link DIR-809 has a denial of service vulnerability (CNVD-2021-37558) CVSS V2: 4.9
CVSS V3: -
Severity: MEDIUM
D-Link DIR-809 is a wireless router using RTOS. D-Link DIR-809 has a denial of service vulnerability. An attacker can use this vulnerability to cause a denial of service.
VAR-202106-2334 No CVE Tiandi Weiye Technology Co., Ltd. RAID management system has logic flaws and vulnerabilities CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Tiandi Weiye is the world's leading provider of smart security solutions. Based on artificial intelligence, big data, cloud computing, Internet of Things and other technologies, it provides smart video products and systems for public security, politics and law, transportation, finance, education, water conservancy, environmental protection and other industries. Solutions and high-quality technical services. The RAID management system of Tiandi Weiye Technology Co., Ltd. has a logic flaw vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2024 No CVE D-Link DIR-809 has a denial of service vulnerability (CNVD-2021-37560) CVSS V2: 4.9
CVSS V3: -
Severity: MEDIUM
D-Link DIR-809 is a wireless router using RTOS. D-Link DIR-809 has a denial of service vulnerability. An attacker can use this leak to cause a denial of service.
VAR-202106-2304 No CVE FC-Series has weak password vulnerability (CNVD-2021-37545) CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
FLIR Systems, Inc. focuses on the design, development, production, marketing and promotion of professional technologies for enhancing situational awareness. Through thermal imaging, visible light imaging, video analysis, measurement and diagnosis, and advanced threat detection systems, we bring innovative sensing solutions into daily life. FC-Series has a weak password vulnerability. The attacker uses the default weak password to log in to the background to obtain sensitive information.
VAR-202106-2311 No CVE FC-Series has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
FLIR Systems, Inc. focuses on the design, development, production, marketing and promotion of professional technologies for enhancing situational awareness. Through thermal imaging, visible light imaging, video analysis, measurement and diagnosis, and advanced threat detection systems, we bring innovative sensing solutions into daily life. FC-Series has a weak password vulnerability. The attacker uses the default weak password to log in to the background to obtain sensitive information.
VAR-202106-2312 No CVE FB-Series has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
FLIR Systems, Inc. focuses on the design, development, production, marketing and promotion of professional technologies for enhancing situational awareness. Through thermal imaging, visible light imaging, video analysis, measurement and diagnosis, and advanced threat detection systems, we bring innovative sensing solutions into daily life. FB-Series has weak password vulnerability. The attacker uses the default weak password to log in to the background to obtain sensitive information.