VARIoT IoT vulnerabilities database

VAR-202106-2257 | No CVE | H3C-ICG1800 has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
H3C-ICG1800 is a router of New H3C Technology Co., Ltd.
H3C-ICG1800 has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2250 | No CVE | Shenzhen Hongdian Technology Co., Ltd. H8922 industrial router has a command execution vulnerability |
CVSS V2: 7.1 CVSS V3: - Severity: HIGH |
The H8922 industrial router uses a high-performance 32-bit MIPS processor and an embedded operating system design.
Shenzhen Hongdian Technology Co., Ltd. H8922 industrial router has a command execution vulnerability. Attackers can use the vulnerability to gain server control authority.
VAR-202106-2246 | No CVE | Aitai Technology Network Management System has a command execution vulnerability |
CVSS V2: 2.1 CVSS V3: - Severity: LOW |
Aitai Technology is a small and medium-sized network solution provider and service provider in China.
Aitai Technology's network management system has a command execution vulnerability, which can be exploited by an attacker to gain server control authority.
VAR-202106-2247 | No CVE | TL-R600VPN has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Pulian Technology Co., Ltd. is a supplier of network communication equipment.
TL-R600VPN has a weak password vulnerability. Attackers use this vulnerability to log in to the system background to obtain sensitive information.
VAR-202106-2256 | No CVE | Shenzhen Jixiang Tengda Technology Co., Ltd. AC11 has a denial of service vulnerability (CNVD-2021-34597) |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
Tenda AC11 is a wireless router that uses RTOS operating system.
Shenzhen Jixiang Tengda Technology Co., Ltd. AC11 has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service.
VAR-202106-2248 | No CVE | Shenzhen Hongdian Technology Co., Ltd. H8922 industrial router has an arbitrary file download vulnerability |
CVSS V2: 2.1 CVSS V3: - Severity: LOW |
The H8922 industrial router uses a high-performance 32-bit MIPS processor and an embedded operating system design.
Shenzhen Hongdian Technology Co., Ltd. H8922 industrial router has an arbitrary file download vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2268 | No CVE | Shenzhen Jixiang Tengda Technology Co., Ltd. AC11 has a denial of service vulnerability |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
Tenda AC11 is a wireless router that uses RTOS operating system.
Shenzhen Jixiang Tengda Technology Co., Ltd. AC11 has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service.
VAR-202106-2253 | No CVE | Unauthorized access vulnerability exists in Shenzhen Leike Industrial Co., Ltd. WF2710 |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
WF2710 is a wireless router.
Shenzhen Leike Industrial Co., Ltd. WF2710 has an unauthorized access vulnerability. Attackers can use the vulnerability to obtain sensitive information.
VAR-202106-2255 | No CVE | Unauthorized access vulnerability exists in Network Camera WV-SPW631L |
CVSS V2: 6.4 CVSS V3: - Severity: MEDIUM |
Matsushita Electric (China) Co., Ltd. is a manufacturer mainly responsible for the sales and after-sales service activities of home appliances, systems, environment, components and other commodities.
Network Camera WV-SPW631L has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2269 | No CVE | Tenda AC11 has a denial of service vulnerability (CNVD-2021-33389) |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
AC11 is a dual-band wireless router developed by Shenzhen Jixiang Tengda Technology Co., Ltd., which is specially designed for large-scale households and is suitable for use in 200M and above fiber optic homes.
Tenda AC11 has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service.
VAR-202106-0541 | CVE-2021-22763 | plural Schneider Electric Product password management vulnerability |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could allow an attacker administrator level access to a device. plural Schneider Electric The product contains a vulnerability related to the password management function.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202106-1622 | CVE-2021-25420 | Galaxy Watch Vulnerability regarding information leakage from log files in plugins |
CVSS V2: 2.1 CVSS V3: 5.5 Severity: MEDIUM |
Improper log management vulnerability in Galaxy Watch PlugIn prior to version 2.2.05.21033151 allows attacker with log permissions to leak Wi-Fi password connected to the user smartphone within log. Samsung Galaxy Apps is a pre-installed app store program for Samsung mobile devices of South Korea's Samsung (Samsung)
VAR-202106-2287 | No CVE | D-Link DIR-600 has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
D-Link DIR-600 is a wireless router produced by D-Link in Taiwan.
D-Link DIR-600 has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2270 | No CVE | Tenda AC11 has a denial of service vulnerability (CNVD-2021-33391) |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
AC11 is a dual-band wireless router developed by Shenzhen Jixiang Tengda Technology Co., Ltd., which is specially designed for large-scale households and is suitable for use in 200M and above fiber optic homes.
Tenda AC11 has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service.
VAR-202106-2288 | No CVE | D-Link DIR-655 has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
D-Link DIR-655 is a wireless router produced by D-Link in Taiwan.
D-Link DIR-655 has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-0543 | CVE-2021-22765 | PowerLogic EGX100 and PowerLogic EGX300 Input confirmation vulnerability |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: Critical |
** UNSUPPORTED WHEN ASSIGNED ** A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code execution via a specially crafted HTTP packet. ** Not supported ** This is a vulnerability in an unsupported product. PowerLogic EGX100 and PowerLogic EGX300 Is vulnerable to input validation.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state
VAR-202106-0542 | CVE-2021-22764 | plural Schneider Electric Product certification vulnerabilities |
CVSS V2: 5.0 CVSS V3: 5.3 Severity: MEDIUM |
A CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could cause loss of connectivity to the device via Modbus TCP protocol when an attacker sends a specially crafted HTTP request. plural Schneider Electric The product contains authentication vulnerabilities.Service operation interruption (DoS) It may be in a state
VAR-202106-1623 | CVE-2021-25421 | Galaxy Watch3 Vulnerability regarding information leakage from log files in plugins |
CVSS V2: 2.1 CVSS V3: 5.5 Severity: MEDIUM |
Improper log management vulnerability in Galaxy Watch3 PlugIn prior to version 2.2.09.21033151 allows attacker with log permissions to leak Wi-Fi password connected to the user smartphone within log. Samsung Galaxy Watch3 is the third-generation smart watch in the Samsung Galaxy Watch series
VAR-202106-2329 | No CVE | Shanghai China Consumer Network Technology Co., Ltd. fire protection platform has logic flaws and loopholes |
CVSS V2: 6.4 CVSS V3: - Severity: MEDIUM |
China Consumer Online Co., Ltd., former name/alias: Shanghai China Consumer Network Technology Co., Ltd., the company is committed to creating industry standards for fire safety, industry standards for fire safety products, standards for smart fire Internet +" One-stop technical operation solutions to promote the innovation of fire safety models and the intelligentization of science and technology.
Shanghai China Consumer Network Technology Co., Ltd. fire-fighting first-level platform has a logic flaw vulnerability. Attackers can use this vulnerability to bypass login to obtain sensitive information.
VAR-202106-2272 | No CVE | Tenda AC11 has a denial of service vulnerability (CNVD-2021-33390) |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
AC11 is a dual-band wireless router developed by Shenzhen Jixiang Tengda Technology Co., Ltd., which is specially designed for large-scale households and is suitable for use in 200M and above fiber optic homes.
Tenda AC11 has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service.