VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202106-2117 No CVE Ruckus Wireless Ruckus R510 has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Ruckus R510 is a wireless access point product of Ruckus Wireless. Ruckus Wireless Ruckus R510 has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2116 No CVE Ruckus Wireless Ruckus R310 has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Ruckus R310 is a wireless access point product of Ruckus Wireless. Ruckus Wireless Ruckus R310 has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2112 No CVE Ruckus 7363 Multimedia Hotzone Wireless AP has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Ruckus 7363 is a wireless product of Ruckus. Ruckus 7363 Multimedia Hotzone Wireless AP has a weak password vulnerability. Attackers can use the vulnerability to log in to the system background and perform unauthorized operations.
VAR-202106-2108 No CVE Ruckus Wireless Ruckus R300 has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Ruckus R300 is a wireless access point product of Ruckus Wireless. Ruckus Wireless Ruckus R300 has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2120 No CVE Ruckus Wireless Ruckus 2825 has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Ruckus 2825 is a wireless router product of Ruckus Wireless. Ruckus Wireless Ruckus 2825 has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2121 No CVE TopVPN6000 has command execution vulnerability CVSS V2: 7.1
CVSS V3: -
Severity: HIGH
Tianrongxin Technology Group (abbreviated as Tianrongxin) is a network security, big data and security cloud service provider. TopVPN6000 has command execution vulnerabilities. An attacker can use this vulnerability to gain control of the server.
VAR-202106-2331 No CVE Tiandiweiye electronic proctoring system has weak password loopholes CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Tiandi Weiye is an intelligent security solution provider. Based on artificial intelligence, big data, cloud computing, Internet of Things and other technologies, it provides intelligent video products, system solutions and High-quality technical services. Tiandiweiye electronic invigilation system has weak password loopholes. Attackers can use this vulnerability to obtain sensitive information.
VAR-202106-2124 No CVE Information disclosure vulnerability exists in Huawei HG8245 CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
The HG8245 is a gateway-type home-side device for Huawei's FTTH solution. It uses G/EPON technology to achieve ultra-broadband access for home/SOHO users. The Huawei HG8245 has an information disclosure vulnerability. Attackers can use vulnerabilities to obtain sensitive information.
VAR-202106-2123 No CVE Rockwell Automation/Allen-Bradley 1756-EN2T/D PLC has a command execution vulnerability CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
Rockwell Automation/Allen-Bradley 1756-EN2T/D PLC is a programmable controller. Rockwell Automation/Allen-Bradley 1756-EN2T/D PLC has a command execution vulnerability. An attacker can use this vulnerability to gain control of the website server.
VAR-202106-2126 No CVE Ruijie Networks Co., Ltd. EG2000SE has a command execution vulnerability CVSS V2: 7.1
CVSS V3: -
Severity: HIGH
Ruijie Networks is a professional network manufacturer with a full range of network equipment product lines and solutions including switches, routers, software, security firewalls, wireless products, storage, etc. Ruijie Networks Co., Ltd. EG2000SE has a command execution vulnerability. Attackers can use the vulnerability to gain control of the server.
VAR-202106-2322 No CVE Shenzhen Kexu Technology Co., Ltd. campus IoT intelligent management system has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
The campus IoT intelligent management system can monitor and control all access devices in real time, centralized management, data statistics, and report presentation. Shenzhen Kexu Technology Co., Ltd. campus IoT intelligent management system has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2164 No CVE China Telecom Tianyi broadband government-enterprise gateway A8C 8+8 AP has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Tianyi broadband government-enterprise gateway is a terminal product customized by China Telecom specifically for brand customers, providing enterprise network solutions. Tianyi Broadband's government-enterprise gateway A8C 8+8 AP has a weak password vulnerability. Attackers use this vulnerability to obtain sensitive information.
VAR-202106-2170 No CVE Ruijie Networks EG2000CE has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Ruijie Networks is a provider of ICT infrastructure and industry solutions. Its main business is the research and development, design and sales of network equipment, network security products and cloud desktop solutions. Ruijie Networks EG2000CE has a weak password vulnerability. The attacker uses the default weak password to log in to the background to obtain sensitive information.
VAR-202106-2169 No CVE Ruijie Networks EG2000SE has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Ruijie Networks is a provider of ICT infrastructure and industry solutions. Its main business is the research and development, design and sales of network equipment, network security products and cloud desktop solutions. Ruijie Networks EG2000SE has a weak password vulnerability. The attacker uses the default weak password to log in to the background to obtain sensitive information.
VAR-202106-1317 CVE-2021-31660 RIOT-OS  Buffer Overflow Vulnerability in Linux CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
RIOT-OS 2021.01 before commit 85da504d2dc30188b89f44c3276fc5a25b31251f contains a buffer overflow which could allow attackers to obtain sensitive information. RIOT RIOT-OS is a set of operating systems used in the field of Internet of Things
VAR-202106-2165 No CVE China Telecom Tianyi broadband government-enterprise gateway A8-B has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Tianyi broadband government-enterprise gateway is a terminal product customized by China Telecom specifically for brand customers, providing enterprise network solutions. Tianyi Broadband's government-enterprise gateway A8-B has a weak password vulnerability. Attackers use this vulnerability to obtain sensitive information.
VAR-202106-1320 CVE-2021-31663 RIOT-OS  Buffer Overflow Vulnerability in Linux CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
RIOT-OS 2021.01 before commit bc59d60be60dfc0a05def57d74985371e4f22d79 contains a buffer overflow which could allow attackers to obtain sensitive information. RIOT RIOT-OS is a set of operating systems used in the field of Internet of Things
VAR-202106-1321 CVE-2021-31664 RIOT-OS  Buffer Overflow Vulnerability in Linux CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
RIOT-OS 2021.01 before commit 44741ff99f7a71df45420635b238b9c22093647a contains a buffer overflow which could allow attackers to obtain sensitive information. RIOT RIOT-OS is a set of operating systems used in the field of Internet of Things
VAR-202106-2167 No CVE Ruijie Networks NBR1300G-E has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Ruijie Networks is a provider of ICT infrastructure and industry solutions. Its main business is the research and development, design and sales of network equipment, network security products and cloud desktop solutions. Ruijie Networks NBR1300G-E has a weak password vulnerability. The attacker uses the default weak password to log in to the background to obtain sensitive information.
VAR-202106-2168 No CVE Ruijie Networks NBR2100G-E has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Ruijie Networks is a provider of ICT infrastructure and industry solutions. Its main business is the research and development, design and sales of network equipment, network security products and cloud desktop solutions. Ruijie Networks NBR2100G-E has a weak password vulnerability. The attacker uses the default weak password to log in to the background to obtain sensitive information.