VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202106-2194 No CVE AXIS M1124 Network Camera has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Axis is an IT company that specializes in providing network video solutions. AXIS M1124 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2195 No CVE Unauthorized access vulnerability exists in HP Officejet 5740 e-All-in-One Printer series CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
HP Officejet 5740 e-All-in-One Printer series is an all-in-one printer from HP Trading (Shanghai) Co., Ltd. The HP Officejet 5740 e-All-in-One Printer series has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2336 No CVE H3C ER G2 series routers have command execution vulnerabilities CVSS V2: 8.3
CVSS V3: -
Severity: HIGH
H3C ER G2 series is a new generation of enterprise-level Gigabit high-performance routers launched by Hangzhou Huasan Communication Technology Co., Ltd. It is positioned in the SMB market for Ethernet/optical/xDSL access, and mainly includes government agencies, Network environment for small and medium-sized enterprises, hotels, schools, hospitals, Internet cafes, etc. H3C ER G2 series routers have a command execution vulnerability, which can be exploited by an attacker to gain control of the server.
VAR-202109-0303 CVE-2021-21570 Dell NetWorker  In  OS  Command injection vulnerability CVSS V2: 4.0
CVSS V3: 4.9
Severity: MEDIUM
Dell NetWorker, versions 18.x and 19.x contain an Information disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and gain access to unauthorized information. Dell EMC NetWorker is a set of unified backup and recovery software from Dell (DELL). The software provides backup and recovery, deduplication, backup reporting, and more
VAR-202109-0302 CVE-2021-21569 Dell NetWorker  Past traversal vulnerability in CVSS V2: 4.0
CVSS V3: 4.9
Severity: MEDIUM
Dell NetWorker, versions 18.x and 19.x contain a Path traversal vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and gain access to unauthorized information. Dell NetWorker is an application of Dell (Dell). Provides Dell's forum discussion function
VAR-202106-2260 No CVE Aitai network management system has command execution vulnerabilities CVSS V2: 7.1
CVSS V3: -
Severity: HIGH
Shanghai Aitai Technology Co., Ltd. is a small and medium-sized network solution provider and service provider in China. Aitai network management system has command execution loopholes. An attacker can use this vulnerability to gain server permissions.
VAR-202106-2261 No CVE Kollmorgen servo drive AKD-P00606-NBPN-000 has a denial of service vulnerability CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
Kollmorgen (Kollmorgen) is the world's leading supplier of motion control systems and accessories. Kollmorgen servo drive AKD-P00606-NBPN-000 has a denial of service vulnerability. Attackers can use this vulnerability to cause the program to crash.
VAR-202106-2262 No CVE H3C ICG 1000 has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
ICG 1000 is a gateway specially launched by H3C for small businesses. H3C ICG 1000 has a weak password vulnerability. Attackers can use this vulnerability to obtain sensitive information.
VAR-202106-2252 No CVE Unauthorized access vulnerability exists in Shenzhen Leike Industrial Co., Ltd. MW5230 CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
MW5230 is a wireless router. Shenzhen Leike Industrial Co., Ltd. MW5230 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2248 No CVE Shenzhen Hongdian Technology Co., Ltd. H8922 industrial router has an arbitrary file download vulnerability CVSS V2: 2.1
CVSS V3: -
Severity: LOW
The H8922 industrial router uses a high-performance 32-bit MIPS processor and an embedded operating system design. Shenzhen Hongdian Technology Co., Ltd. H8922 industrial router has an arbitrary file download vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2265 No CVE HP Trading (Shanghai) Co., Ltd. HP-ENVY-7640 has an unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
The HP-ENVY-7640 series printer is an all-in-one printer from Hewlett-Packard Company. HP Trading (Shanghai) Co., Ltd. HP-ENVY-7640 has an unauthorized access vulnerability. Attackers can use this vulnerability to directly access the printer control interface without logging in.
VAR-202106-2263 No CVE A weak password vulnerability exists in the picture server of Hangzhou Hikvision System Technology Co., Ltd. CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Hangzhou Hikvision System Technology Co., Ltd. is a smart IoT solution provider and operation service provider with video as the core. The image server of Hangzhou Hikvision System Technology Co., Ltd. has a weak password vulnerability. Attackers can use the vulnerability to obtain sensitive information.
VAR-202106-2268 No CVE Shenzhen Jixiang Tengda Technology Co., Ltd. AC11 has a denial of service vulnerability CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
Tenda AC11 is a wireless router that uses RTOS operating system. Shenzhen Jixiang Tengda Technology Co., Ltd. AC11 has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service.
VAR-202106-2246 No CVE Aitai Technology Network Management System has a command execution vulnerability CVSS V2: 2.1
CVSS V3: -
Severity: LOW
Aitai Technology is a small and medium-sized network solution provider and service provider in China. Aitai Technology's network management system has a command execution vulnerability, which can be exploited by an attacker to gain server control authority.
VAR-202106-2245 No CVE H3C ER G2 series routers have binary vulnerabilities CVSS V2: 4.3
CVSS V3: -
Severity: MEDIUM
H3C ER G2 series is a new generation of enterprise-level Gigabit high-performance routers launched by Hangzhou Huasan Communication Technology Co., Ltd. H3C ER G2 series routers have a binary vulnerability, which can be exploited by an attacker to cause a denial of service.
VAR-202106-2255 No CVE Unauthorized access vulnerability exists in Network Camera WV-SPW631L CVSS V2: 6.4
CVSS V3: -
Severity: MEDIUM
Matsushita Electric (China) Co., Ltd. is a manufacturer mainly responsible for the sales and after-sales service activities of home appliances, systems, environment, components and other commodities. Network Camera WV-SPW631L has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2267 No CVE Unauthorized access vulnerability exists in HP Officejet 6700 Premium e-All-in-One CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
HP Officejet 6700 Premium e-All-in-One is an all-in-one printer from HP Trading (Shanghai) Co., Ltd. The HP Officejet 6700 Premium e-All-in-One has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2266 No CVE Unauthorized access vulnerability exists in HP DeskJet 2600 All-in-One Printer series CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
HP DeskJet 2600 All-in-One Printer series is an all-in-one printer from HP Trading (Shanghai) Co., Ltd. An unauthorized access vulnerability exists in the HP DeskJet 2600 All-in-One Printer series. Attackers can use the vulnerability to obtain sensitive information.
VAR-202106-2250 No CVE Shenzhen Hongdian Technology Co., Ltd. H8922 industrial router has a command execution vulnerability CVSS V2: 7.1
CVSS V3: -
Severity: HIGH
The H8922 industrial router uses a high-performance 32-bit MIPS processor and an embedded operating system design. Shenzhen Hongdian Technology Co., Ltd. H8922 industrial router has a command execution vulnerability. Attackers can use the vulnerability to gain server control authority.
VAR-202106-2249 No CVE DVA-2800 management platform and DSL-2888A management platform have logic flaws and vulnerabilities CVSS V2: 6.4
CVSS V3: -
Severity: MEDIUM
D-Link Electronic Equipment (Shanghai) Co., Ltd. is a company mainly engaged in network equipment, wireless equipment, switches and other projects. The DVA-2800 management platform and DSL-2888A management platform have logic flaws and vulnerabilities, which can be exploited by attackers to obtain sensitive information.