VARIoT IoT vulnerabilities database

VAR-202106-2153 | No CVE | NETGEAR WNR1000v2 router has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
The NETGEAR WNR1000v2 router is a wireless router device.
The NETGEAR WNR1000v2 router has a weak password vulnerability. Attackers can use this vulnerability to control the device, obtain sensitive information and perform unauthorized operations.
VAR-202106-2145 | No CVE | AXIS XIS Q1602 Network Camera has unauthorized access vulnerability |
CVSS V2: 6.4 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions. It is the global market leader in network video, driving the transition from analog to digital video surveillance. Axis' monitoring products and solutions are based on an open and innovative technology platform, dedicated to security monitoring and remote monitoring.
AXIS XIS Q1602 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2157 | No CVE | NETGEAR WNR2000v2 router has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
NETGEAR WNR2000v2 router is a wireless router device.
The NETGEAR WNR2000v2 router has a weak password vulnerability. Attackers can use this vulnerability to control the device, obtain sensitive information and perform unauthorized operations.
VAR-202106-2144 | No CVE | NETGEAR WNR2020 router has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
NETGEAR WNR2020 router is a wireless router device.
The NETGEAR WNR2020 router has a weak password vulnerability. Attackers can use this vulnerability to control the device, obtain sensitive information and perform unauthorized operations.
VAR-202106-1176 | CVE-2021-33346 | DSL-2888A Illegal authentication vulnerability in firmware |
CVSS V2: 5.0 CVSS V3: 9.8 Severity: CRITICAL |
There is an arbitrary password modification vulnerability in a D-LINK DSL-2888A router product. An attacker can use this vulnerability to modify the password of the admin user without authorization. DSL-2888A The firmware contains a vulnerability related to unauthorized authentication.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. D-link DSL-2888A is a unified service router of China D-link Corporation.
D-LINK DSL-2888A has a security loophole
VAR-202106-2160 | No CVE | NETGEAR WNDR3300 router has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
The NETGEAR WNDR3300 router is a wireless router device.
The NETGEAR WNDR3300 router has a weak password vulnerability. Attackers can use this vulnerability to control the device, obtain sensitive information and perform unauthorized operations.
VAR-202106-2152 | No CVE | NETGEAR WNDR4300 router has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
The NETGEAR WNDR4300 router is a wireless router device.
The NETGEAR WNDR4300 router has a weak password vulnerability. Attackers can use this vulnerability to control the device, obtain sensitive information and perform unauthorized operations.
VAR-202106-2151 | No CVE | NETGEAR WNDR3700v4 router has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
The NETGEAR WNDR3700v4 router is a wireless router device.
The NETGEAR WNDR3700v4 router has a weak password vulnerability. Attackers can use this vulnerability to control the device, obtain sensitive information and perform unauthorized operations.
VAR-202106-2147 | No CVE | AXIS Q1755 Network Camera has unauthorized access vulnerability |
CVSS V2: 6.4 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions. It is the global market leader in network video, driving the transition from analog to digital video surveillance. Axis' monitoring products and solutions are based on an open and innovative technology platform, dedicated to security monitoring and remote monitoring.
AXIS Q1755 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2156 | No CVE | NETGEAR WNR2000v3 router has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
NETGEAR WNR2000v3 router is a wireless router device.
The NETGEAR WNR2000v3 router has a weak password vulnerability. Attackers can use this vulnerability to control the device, obtain sensitive information and perform unauthorized operations.
VAR-202106-2136 | No CVE | D-Link DIR-809 has a denial of service vulnerability (CNVD-2021-36512) |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
D-Link DIR-809 is a wireless router using RTOS.
D-Link DIR-809 has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service attack.
VAR-202106-2148 | No CVE | Finetree 5MP Network Camera has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
5MP Network Camera is a camera product.
Finetree 5MP Network Camera has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2139 | No CVE | D-Link DIR-809 has a stack overflow vulnerability |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
D-Link DIR-809 is a wireless router, using RTOS system.
D-Link DIR-809 has a stack overflow vulnerability, which can be exploited by an attacker to cause a denial of service attack.
VAR-202106-2142 | No CVE | Schneider Electric (China) Co., Ltd. power monitoring PowerLogic ION7650 has unauthorized vulnerabilities |
CVSS V2: 6.4 CVSS V3: - Severity: MEDIUM |
Schneider Electric (China) Co., Ltd. is a company whose main business includes electric power, industrial automation, infrastructure, energy efficiency, energy, building automation and security electronics, data centers and smart living spaces.
Schneider Electric (China) Co., Ltd. power monitoring PowerLogic ION7650 has an unauthorized vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2134 | No CVE | Shenzhen UTP Technology Co., Ltd. UTP-R3050-5GP has a SQL injection vulnerability |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
Established in 2005, UTEPO is an industrial communication and intelligent Internet of Things solution provider with "Internet and Electricity Speed Connection" technology as the core. Based on technological innovation, it is a smart park, smart security, smart city, Provide smart IoT solutions in fields such as smart agriculture and smart manufacturing.
Shenzhen UTP Technology Co., Ltd. UTP-R3050-5GP has a SQL injection vulnerability. Attackers can use the vulnerability to obtain sensitive information in the database.
VAR-202106-2135 | No CVE | D-Link DIR-809 has a denial of service vulnerability (CNVD-2021-36511) |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
D-Link DIR-809 is a wireless router using RTOS.
D-Link DIR-809 has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service attack.
VAR-202106-2161 | No CVE | NETGEAR WGR614v7 router has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
NETGEAR WGR614v7 router is a wireless router device.
The NETGEAR WGR614v7 router has a weak password vulnerability. Attackers can use this vulnerability to control the device, obtain sensitive information and perform unauthorized operations.
VAR-202106-2333 | No CVE | Xiamen Sixin Communication Technology Co., Ltd. RMP router management platform has logic flaws and vulnerabilities |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Xiamen Sixin Communication Technology Co., Ltd. is a backbone enterprise in the wireless communication field of China's Internet of Things. It is a high-tech enterprise covering products, services and management activities with strong values of "integrity, trust, confidence, and belief".
The RMP router management platform of Xiamen Sixin Communication Technology Co., Ltd. has a logic flaw vulnerability, which can be used by attackers to obtain sensitive data.
VAR-202106-2146 | No CVE | AXIS Q1604 Network Camera has unauthorized access vulnerability |
CVSS V2: 6.4 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions. It is the global market leader in network video, driving the transition from analog to digital video surveillance. Axis' monitoring products and solutions are based on an open and innovative technology platform, dedicated to security monitoring and remote monitoring.
AXIS Q1604 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2337 | No CVE | Unauthorized access vulnerability exists in Dell B3460DN monochrome laser printer |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
The business scope of Dell (China) Co., Ltd. includes: manufacturing, assembling, researching and developing computer products, mobile phone products, network communication equipment (routers, switches, network data center products), etc.
The Dell B3460DN monochrome laser printer has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.