VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202107-1709 No CVE Any file download vulnerability exists in the next-generation firewall security gateway of Feiyuxing CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Chengdu Feiyuxing Technology Co., Ltd. is one of the few local enterprises in the industry with independent intellectual property rights and independent research and development capabilities. It is a high-tech enterprise focusing on product innovation and research in the data communication industry and the Internet of Things industry. There is an arbitrary file download vulnerability in the Feiyuxing next-generation firewall security gateway, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1713 No CVE Hikvision security access gateway has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Hangzhou Hikvision Digital Technology Co., Ltd. is a leading provider of security products and industry solutions. Hikvision security access gateway has weak password vulnerability. Attackers can use this vulnerability to log in to the background to obtain sensitive information.
VAR-202107-1712 No CVE Any file download vulnerability exists in Hikvision's secure access gateway CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Hangzhou Hikvision Digital Technology Co., Ltd. is a leading provider of security products and industry solutions. The Hikvision secure access gateway has an arbitrary file download vulnerability. Attackers can use this vulnerability to obtain sensitive information.
VAR-202107-1711 No CVE Rascomda Technology Development Co., Ltd. security router has an arbitrary file download vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Raisecomda Technology Development Co., Ltd. focuses on the field of optical fiber broadband access, and is committed to the integration of optical fiber technology, Ethernet technology and broadband access technology. The security router of Rascomda Technology Development Co., Ltd. has an arbitrary file download vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1710 No CVE Any file download vulnerability exists in the multi-service security gateway of Shanghai Huayi Technology Group Co., Ltd. CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Shanghai Huayi Technology Group Co., Ltd. is a company mainly engaged in the research and development, manufacturing of test benches in the field of automotive powertrain and the provision of related technical services. An arbitrary file download vulnerability exists in the multi-service security gateway of Shanghai Huayi Technology Group Co., Ltd., which can be exploited by attackers to obtain sensitive information.
VAR-202107-1885 No CVE Unauthorized access vulnerability exists in AXIS 240Q Video Server CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Axis is an IT company that specializes in providing network video solutions. AXIS 240Q Video Server has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-0946 CVE-2021-29297 Emerson GE Automation Proficy Machine Edition  Classic buffer overflow vulnerability in CVSS V2: 2.6
CVSS V3: 5.3
Severity: MEDIUM
Buffer Overflow in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service and application crash via crafted traffic from a Man-in-the-Middle (MITM) attack to the component "FrameworX.exe" in the module "MSVCR100.dll"
VAR-202107-1876 No CVE AXIS P3344 Network Camera has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Axis is an IT company that specializes in providing network video solutions. AXIS P3344 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1874 No CVE AXIS M3025 Network Camera has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Axis is an IT company that specializes in providing network video solutions. AXIS M3025 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1871 No CVE AXIS M3114 Network Camera has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Axis is an IT company that specializes in providing network video solutions. AXIS M3114 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1870 No CVE Unauthorized access vulnerability exists in Axis 2120 Network Camera CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Axis is an IT company that specializes in providing network video solutions. Axis 2120 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1872 No CVE AXIS M5014 Network Camera has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Axis is an IT company that specializes in providing network video solutions. AXIS M5014 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1901 No CVE An SQL injection vulnerability exists in the property integrated billing management cloud platform of Shenzhen China Electric Power Technology Co., Ltd. CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
The property integrated billing management system is based on cloud computing, the Internet of Things and advanced smart billing management technology, which realizes the flexible access of power system smart electricity data and other smart terminal data, and supports 4G, RS-485, Ethernet and other communication methods. Enable data interconnection, realize online online recharge, SMS reminder and balance inquiry, etc. Shenzhen China Electric Power Technology Co., Ltd. property integrated billing management cloud platform has SQL injection vulnerabilities. Attackers can use vulnerabilities to obtain sensitive information in the database.
VAR-202107-1881 No CVE Unauthorized access vulnerability exists in AXIS 206M Network Camera CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Axis is an IT company that specializes in providing network video solutions. AXIS 206M Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1878 No CVE Unauthorized access vulnerability exists in Cisco IP Phone CP-8865 CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Cisco IP Phone CP-8865 is an enterprise-class IP phone. Cisco IP Phone CP-8865 has an unauthorized access vulnerability. Attackers can use vulnerabilities to obtain sensitive information.
VAR-202107-1879 No CVE AXIS 2130R PTZ Network Camera has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Axis is an IT company that specializes in providing network video solutions. AXIS 2130R PTZ Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1715 CVE-2025-34044 WIFISKY 7-layer flow control router has command execution vulnerabilities CVSS V2: 7.1
CVSS V3: -
Severity: Critical
A remote command injection vulnerability exists in the confirm.php interface of the WIFISKY 7-layer Flow Control Router via a specially-crafted HTTP GET request to the t parameter. Insufficient input validation allows unauthenticated attackers to execute arbitrary OS commands. Shenzhen Airspace Technology Co., Ltd. ("Airspace Technology" for short) is a network communication equipment supplier rooted in Shenzhen and radiating the world. An attacker can use this vulnerability to gain control of the server
VAR-202107-1884 No CVE Unauthorized access vulnerability exists in AXIS 241Q Video Server CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Axis is an IT company that specializes in providing network video solutions. AXIS 241Q Video Server has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1887 No CVE AXIS P1214 Network Camera has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Axis is an IT company that specializes in providing network video solutions. AXIS P1214 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1883 No CVE Unauthorized access vulnerability exists in AXIS 241S Video Server CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Axis is an IT company that specializes in providing network video solutions. AXIS 241S Video Server has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.