VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202105-1581 No CVE Feiyuxing home smart router has logic flaws and loopholes CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Chengdu Feiyuxing Technology Co., Ltd. was established in 2002 as a high-tech enterprise focusing on product innovation and research and development in the data communication industry and the Internet of Things industry. Feiyuxing home intelligent routing has logic flaws and loopholes. Attackers can use the vulnerability to bypass the login by modifying the return packet and view sensitive information.
VAR-202105-1684 No CVE Unauthorized access vulnerability exists in Cisco Wireless-G Internet Home Monitoring Camera CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Cisco is the world's leading provider of network solutions. Cisco Wireless-G Internet Home Monitoring Camera has an unauthorized access vulnerability. Attackers can use vulnerabilities to obtain sensitive information.
VAR-202105-1709 No CVE Panasonic-SF335 camera has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Matsushita Electric (China) Co., Ltd. is an electronics manufacturer engaged in the production and sales of various electrical products. The Panasonic-SF335 camera has an unauthorized access vulnerability. Attackers can use vulnerabilities to obtain sensitive information.
VAR-202105-1575 No CVE A weak password vulnerability exists in the D-Link router management page CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
D-Link Electronic Equipment (Shanghai) Co., Ltd. was established on August 13, 2002. The company's business scope includes routers, network cards, hubs, switches, converters, etc. in the region. The D-Link router management page has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202105-1577 No CVE Lenovo NetMaster Security Gateway has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Beijing Wangyu Xingyun Information Technology Co., Ltd. was renamed from Lenovo Wangyu Technology (Beijing) Co., Ltd., and its predecessor was Lenovo Group Information Security Division. The main business covers network boundary security protection, application and data security protection, and network-wide security risk management. The Lenovo Netmaster Security Gateway has weak password vulnerabilities. The attacker uses a weak password to log in to the background to obtain sensitive information.
VAR-202105-1583 No CVE Huawei S9312 has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
S9312 is a switch. Huawei S9312 has a weak password vulnerability. The attacker uses a weak password to log in to the background to obtain sensitive information.
VAR-202105-1580 No CVE Huawei S9306 has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
S9306 is a routing switch, POE switch. Huawei S9306 has a weak password vulnerability. The attacker uses a weak password to log in to the background to obtain sensitive information.
VAR-202105-1582 No CVE Shenzhen Tenghu IOT Technology Co., Ltd. AC9563 has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Shenzhen Tenghu IOT Technology Co., Ltd. was established in August 2013. It is an Internet technology company integrating R&D, manufacturing, sales and service of commercial wireless network products. Shenzhen Tenghu IOT Technology Co., Ltd. AC9563 has a weak password vulnerability. Attackers can use weak passwords to log in to the background to obtain sensitive information.
VAR-202105-1579 No CVE Ruijie Networks ASME access shared management engine has logic flaws and vulnerabilities CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
ASME Access Sharing Management Engine is an anti-agent product based on DPI application layer detection. Ruijie Networks’ ASME access shared management engine has logic flaws and vulnerabilities. The attacker can view and modify the returned packet by capturing the packet, fill in the password at will, and successfully log in to the background to obtain sensitive information.
VAR-202105-1584 No CVE Feiyuxing router has an information disclosure vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Chengdu Feiyuxing Technology Co., Ltd. was established in 2002 as a high-tech enterprise focusing on product innovation and research and development in the data communication industry and the Internet of Things industry. The Feiyuxing router has an information disclosure vulnerability. Attackers can use vulnerabilities to obtain sensitive information.
VAR-202105-1585 No CVE Network Video Server network video server has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Network Video Server is a network video server. The Network Video Server network video server has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202105-1578 No CVE Vigor series products have logic flaws and vulnerabilities CVSS V2: 6.4
CVSS V3: -
Severity: MEDIUM
Shanghai Juyi Technology Development Co., Ltd., legal representative: Wang Nan, registered capital: 1 million yuan, address: JT1225, Room 2201, No. 888 Moyu South Road, Anting Town, Jiading District, Shanghai, Business Scope: General Projects: Technical Services, Technical Development , Technology consultation, technology exchange, technology transfer, technology promotion; software development; computer software and hardware and auxiliary equipment wholesale, etc. Vigor series products have logic flaws, which can be exploited by attackers to obtain sensitive information.
VAR-202105-1686 No CVE Command execution vulnerability exists in DrayTek Vigor2960 (CNVD-2021-28719) CVSS V2: 7.1
CVSS V3: -
Severity: HIGH
Vigor2960 is a product of DrayTek in Taiwan, China. It is a load balancing router and VPN gateway device. DrayTek Vigor2960 has a command execution vulnerability, which can be exploited by attackers to obtain ROOT privileges.
VAR-202105-1687 No CVE Command execution vulnerability exists in DrayTek Vigor2960 (CNVD-2021-28718) CVSS V2: 7.1
CVSS V3: -
Severity: HIGH
Vigor2960 is a product of DrayTek in Taiwan, China. It is a load balancing router and VPN gateway device. DrayTek Vigor2960 has a command execution vulnerability, which can be exploited by attackers to obtain ROOT privileges.
VAR-202105-1586 No CVE DIR-816 750M11AC wireless router has unauthorized access vulnerability CVSS V2: 3.3
CVSS V3: -
Severity: LOW
D-Link DIR-816 is a wireless router under D-Link's D-Link brand, manufactured in mainland China. The DIR-816 750M11AC wireless router has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202105-1592 No CVE N-speed Gigabit multi-network wireless broadband sharing device has a command execution vulnerability CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
Sapido was established in Tainan in 2006. It is a brand of network communication products and Internet of Things that has obtained the Taiwanese Smile Mark. The N-speed Gigabit multi-network wireless broadband sharing device has a command execution vulnerability, which can be used by an attacker to gain control of the server.
VAR-202105-1621 No CVE IDS-WEBCAM has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
IDS-WEBCAM is an industrial camera. IDS-WEBCAM has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-0506 CVE-2021-20576 IBM Security Verify Access  Vulnerability in CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
IBM Security Verify Access 20.07 could allow a remote attacker to send a specially crafted HTTP GET request that could cause the application to crash. IBM Security Verify Access Contains an unspecified vulnerability.Denial of service (DoS) It may be put into a state. IBM Application Gateway is an application gateway of IBM Corporation in the United States. Provides a containerized secure Web reverse proxy, which is designed to be in front of your application and seamlessly add authentication and authorization protection to your application. An information disclosure vulnerability exists in IBM Application Gateway. The vulnerability stems from the fact that the program allows web pages to be stored locally for other users on the system to read. Attackers may use this vulnerability to obtain sensitive information
VAR-202105-1589 No CVE A weak password vulnerability exists in the AR web management platform CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
The business of Huawei Technologies Co., Ltd. includes switches, transmission equipment, data communication equipment, broadband multimedia equipment, power supplies, wireless communication equipment, microelectronics products, software, etc. The AR Web management platform has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-0505 CVE-2021-20575 IBM Security Verify Access  Vulnerability in insecure storage of important information in CVSS V2: 2.1
CVSS V3: 3.3
Severity: LOW
IBM Security Verify Access 20.07 allows web pages to be stored locally which can be read by another user on the system. X-Force ID: 199278. Vendor exploits this vulnerability IBM X-Force ID: 199278 Is published as.Information may be obtained. IBM Application Gateway is an application gateway of IBM Corporation in the United States. Provides a containerized secure Web reverse proxy, which is designed to be in front of your application and seamlessly add authentication and authorization protection to your application. Attackers may use this vulnerability to obtain sensitive information