VARIoT IoT vulnerabilities database

VAR-202106-2194 | No CVE | AXIS M1124 Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS M1124 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2195 | No CVE | Unauthorized access vulnerability exists in HP Officejet 5740 e-All-in-One Printer series |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
HP Officejet 5740 e-All-in-One Printer series is an all-in-one printer from HP Trading (Shanghai) Co., Ltd.
The HP Officejet 5740 e-All-in-One Printer series has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2336 | No CVE | H3C ER G2 series routers have command execution vulnerabilities |
CVSS V2: 8.3 CVSS V3: - Severity: HIGH |
H3C ER G2 series is a new generation of enterprise-level Gigabit high-performance routers launched by Hangzhou Huasan Communication Technology Co., Ltd. It is positioned in the SMB market for Ethernet/optical/xDSL access, and mainly includes government agencies, Network environment for small and medium-sized enterprises, hotels, schools, hospitals, Internet cafes, etc.
H3C ER G2 series routers have a command execution vulnerability, which can be exploited by an attacker to gain control of the server.
VAR-202109-0303 | CVE-2021-21570 | Dell NetWorker In OS Command injection vulnerability |
CVSS V2: 4.0 CVSS V3: 4.9 Severity: MEDIUM |
Dell NetWorker, versions 18.x and 19.x contain an Information disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and gain access to unauthorized information. Dell EMC NetWorker is a set of unified backup and recovery software from Dell (DELL). The software provides backup and recovery, deduplication, backup reporting, and more
VAR-202109-0302 | CVE-2021-21569 | Dell NetWorker Past traversal vulnerability in |
CVSS V2: 4.0 CVSS V3: 4.9 Severity: MEDIUM |
Dell NetWorker, versions 18.x and 19.x contain a Path traversal vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and gain access to unauthorized information. Dell NetWorker is an application of Dell (Dell). Provides Dell's forum discussion function
VAR-202106-2260 | No CVE | Aitai network management system has command execution vulnerabilities |
CVSS V2: 7.1 CVSS V3: - Severity: HIGH |
Shanghai Aitai Technology Co., Ltd. is a small and medium-sized network solution provider and service provider in China.
Aitai network management system has command execution loopholes. An attacker can use this vulnerability to gain server permissions.
VAR-202106-2261 | No CVE | Kollmorgen servo drive AKD-P00606-NBPN-000 has a denial of service vulnerability |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
Kollmorgen (Kollmorgen) is the world's leading supplier of motion control systems and accessories.
Kollmorgen servo drive AKD-P00606-NBPN-000 has a denial of service vulnerability. Attackers can use this vulnerability to cause the program to crash.
VAR-202106-2262 | No CVE | H3C ICG 1000 has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
ICG 1000 is a gateway specially launched by H3C for small businesses.
H3C ICG 1000 has a weak password vulnerability. Attackers can use this vulnerability to obtain sensitive information.
VAR-202106-2252 | No CVE | Unauthorized access vulnerability exists in Shenzhen Leike Industrial Co., Ltd. MW5230 |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
MW5230 is a wireless router.
Shenzhen Leike Industrial Co., Ltd. MW5230 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2248 | No CVE | Shenzhen Hongdian Technology Co., Ltd. H8922 industrial router has an arbitrary file download vulnerability |
CVSS V2: 2.1 CVSS V3: - Severity: LOW |
The H8922 industrial router uses a high-performance 32-bit MIPS processor and an embedded operating system design.
Shenzhen Hongdian Technology Co., Ltd. H8922 industrial router has an arbitrary file download vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2265 | No CVE | HP Trading (Shanghai) Co., Ltd. HP-ENVY-7640 has an unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
The HP-ENVY-7640 series printer is an all-in-one printer from Hewlett-Packard Company.
HP Trading (Shanghai) Co., Ltd. HP-ENVY-7640 has an unauthorized access vulnerability. Attackers can use this vulnerability to directly access the printer control interface without logging in.
VAR-202106-2263 | No CVE | A weak password vulnerability exists in the picture server of Hangzhou Hikvision System Technology Co., Ltd. |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Hangzhou Hikvision System Technology Co., Ltd. is a smart IoT solution provider and operation service provider with video as the core.
The image server of Hangzhou Hikvision System Technology Co., Ltd. has a weak password vulnerability. Attackers can use the vulnerability to obtain sensitive information.
VAR-202106-2268 | No CVE | Shenzhen Jixiang Tengda Technology Co., Ltd. AC11 has a denial of service vulnerability |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
Tenda AC11 is a wireless router that uses RTOS operating system.
Shenzhen Jixiang Tengda Technology Co., Ltd. AC11 has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service.
VAR-202106-2246 | No CVE | Aitai Technology Network Management System has a command execution vulnerability |
CVSS V2: 2.1 CVSS V3: - Severity: LOW |
Aitai Technology is a small and medium-sized network solution provider and service provider in China.
Aitai Technology's network management system has a command execution vulnerability, which can be exploited by an attacker to gain server control authority.
VAR-202106-2245 | No CVE | H3C ER G2 series routers have binary vulnerabilities |
CVSS V2: 4.3 CVSS V3: - Severity: MEDIUM |
H3C ER G2 series is a new generation of enterprise-level Gigabit high-performance routers launched by Hangzhou Huasan Communication Technology Co., Ltd.
H3C ER G2 series routers have a binary vulnerability, which can be exploited by an attacker to cause a denial of service.
VAR-202106-2255 | No CVE | Unauthorized access vulnerability exists in Network Camera WV-SPW631L |
CVSS V2: 6.4 CVSS V3: - Severity: MEDIUM |
Matsushita Electric (China) Co., Ltd. is a manufacturer mainly responsible for the sales and after-sales service activities of home appliances, systems, environment, components and other commodities.
Network Camera WV-SPW631L has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2267 | No CVE | Unauthorized access vulnerability exists in HP Officejet 6700 Premium e-All-in-One |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
HP Officejet 6700 Premium e-All-in-One is an all-in-one printer from HP Trading (Shanghai) Co., Ltd.
The HP Officejet 6700 Premium e-All-in-One has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2266 | No CVE | Unauthorized access vulnerability exists in HP DeskJet 2600 All-in-One Printer series |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
HP DeskJet 2600 All-in-One Printer series is an all-in-one printer from HP Trading (Shanghai) Co., Ltd.
An unauthorized access vulnerability exists in the HP DeskJet 2600 All-in-One Printer series. Attackers can use the vulnerability to obtain sensitive information.
VAR-202106-2250 | No CVE | Shenzhen Hongdian Technology Co., Ltd. H8922 industrial router has a command execution vulnerability |
CVSS V2: 7.1 CVSS V3: - Severity: HIGH |
The H8922 industrial router uses a high-performance 32-bit MIPS processor and an embedded operating system design.
Shenzhen Hongdian Technology Co., Ltd. H8922 industrial router has a command execution vulnerability. Attackers can use the vulnerability to gain server control authority.
VAR-202106-2249 | No CVE | DVA-2800 management platform and DSL-2888A management platform have logic flaws and vulnerabilities |
CVSS V2: 6.4 CVSS V3: - Severity: MEDIUM |
D-Link Electronic Equipment (Shanghai) Co., Ltd. is a company mainly engaged in network equipment, wireless equipment, switches and other projects.
The DVA-2800 management platform and DSL-2888A management platform have logic flaws and vulnerabilities, which can be exploited by attackers to obtain sensitive information.