VARIoT IoT vulnerabilities database

VAR-202105-1611 | No CVE | D-Link DIR-816 router has a binary vulnerability (CNVD-2021-27693) |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
DIR-816 is a wireless router under the D-Link brand, manufactured in mainland China.
The D-Link DIR-816 router has a binary vulnerability, which can be exploited by an attacker to cause the service program to crash.
VAR-202105-0811 | CVE-2021-25849 | Moxa Camera VPort 06EC-2V has a denial of service vulnerability |
CVSS V2: 7.8 CVSS V3: 7.5 Severity: HIGH |
An integer underflow was discovered in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, improper validation of the PortID TLV leads to Denial of Service via a crafted lldp packet. MOXA Camera VPort 06EC-2V is a camera equipment of MOXA, Taiwan.
Moxa Camera VPort 06EC-2V has security vulnerabilities. Attackers can cause denial of service through elaborate lldp packets
VAR-202105-1651 | No CVE | D-Link DIR-816 router has a binary vulnerability |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
DIR-816 is a wireless router under the D-Link brand, manufactured in mainland China.
The D-Link DIR-816 router has a binary vulnerability, which can be exploited by an attacker to cause the service program to crash.
VAR-202105-1613 | No CVE | Huawei Technologies Co., Ltd. Secoway USG5150 has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Secoway-USG5150 is a security gateway product of Huawei Technologies Co., Ltd.
Huawei Technologies Co., Ltd. Secoway USG5150 has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202105-1650 | No CVE | D-Link DIR-816 router has a binary vulnerability (CNVD-2021-27694) |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
DIR-816 is a wireless router under the D-Link brand, manufactured in mainland China.
The D-Link DIR-816 router has a binary vulnerability, which can be exploited by an attacker to cause the service program to crash.
VAR-202105-1659 | No CVE | Shenzhen Leike Industrial Co., Ltd. NR255P has a weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
NR255P is a new generation of high-performance QOS router developed by Shenzhen Leike Industrial Co., Ltd., which is tailor-made for small businesses, tiny Internet cafes, and rental houses.
Shenzhen Leike Industrial Co., Ltd. NR255P has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202105-1658 | No CVE | New H3C Technology Co., Ltd. ER5200G2, ER3100G2, ER3260G2 have weak password vulnerabilities |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
ER5200G2, ER3100G2, and ER3260G2 are a new generation of high-performance enterprise-class routers launched by New H3C Technology Co., Ltd.
New H3C Technology Co., Ltd. ER5200G2, ER3100G2, and ER3260G2 have weak password vulnerabilities, which can be exploited by attackers to obtain sensitive information.
VAR-202105-1647 | No CVE | Shenzhen Leike Industrial Co., Ltd. NR285G has a weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
NR285G is a router of Shenzhen Leike Industrial Co., Ltd.
Shenzhen Leike Industrial Co., Ltd. NR285G has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202105-1657 | CVE-2021-42659 | Shenzhen Tenda Technology Co.,Ltd. of AC9 Buffer error vulnerability in firmware |
CVSS V2: 6.1 CVSS V3: 6.5 Severity: MEDIUM |
There is a buffer overflow vulnerability in the Web server httpd of the router in Tenda router devices such as Tenda AC9 V1.0 V15.03.02.19(6318) and Tenda AC9 V3.0 V15.03.06.42_multi. When setting the virtual service, the httpd program will crash and exit when the super-long list parameter occurs. Shenzhen Tenda Technology Co.,Ltd. of AC9 A buffer error vulnerability exists in the firmware.Service operation interruption (DoS) It may be in a state. AC9 is a 1200M 11AC wireless router with Gigabit Ethernet port launched by Shenzhen Jixiang Tengda Technology Co., Ltd. in 2016.
Tenda AC9 has a denial of service vulnerability, which can be exploited by attackers to cause the program to crash
VAR-202105-1652 | No CVE | TP-LINK TL-ER6110G, TL-ER6120G, TL-ER6220G routers have weak password vulnerabilities |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
TL-ER6110G, TL-ER6120G, and TL-ER6220G are all TP-LINK routers.
TP-LINK TL-ER6110G, TL-ER6120G, and TL-ER6220G routers have weak password vulnerabilities, which can be exploited by attackers to obtain sensitive information.
VAR-202105-1655 | No CVE | Shenzhen Leike Industrial Co., Ltd. NR238 has a weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
NR238 is a router of Shenzhen Leike Industrial Co., Ltd.
Shenzhen Leike Industrial Co., Ltd. NR238 has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202105-1653 | No CVE | D-Link Electronic Equipment (Shanghai) Co., Ltd. DSL-2730E has a weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
DSL-2730E is a router of D-Link Electronic Equipment (Shanghai) Co., Ltd.
D-Link Electronic Equipment (Shanghai) Co., Ltd. DSL-2730E has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202105-1656 | No CVE | Tenda AC9 has a denial of service vulnerability (CNVD-2021-24932) |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
AC9 is a 1200M 11AC wireless router with Gigabit Ethernet port launched by Shenzhen Jixiang Tengda Technology Co., Ltd. in 2016.
Tenda AC9 has a denial of service vulnerability, which can be exploited by attackers to cause the program to crash.
VAR-202105-1654 | No CVE | Guangzhou Jiu'an Intelligent Technology Co., Ltd. JA7208 has a logic defect vulnerability |
CVSS V2: 6.4 CVSS V3: - Severity: MEDIUM |
Guangzhou Jiu'an Intelligent Technology Co., Ltd. is the world's leading provider of mobile image transmission infrastructure and IoT platforms.
Guangzhou Jiu'an Intelligent Technology Co., Ltd. JA7208 has a logic flaw vulnerability, which can be used by attackers to bypass login verification.
VAR-202105-1664 | No CVE | Shenzhen Leike Industrial Co., Ltd. NR235P has a weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
NR235P is a type of broadband router for small business equipment.
Shenzhen Leike Industrial Co., Ltd. NR235P has a weak password vulnerability. Attackers can use weak passwords to log in to the background to obtain sensitive information.
VAR-202105-1667 | No CVE | H3C NER324 has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
H3C NER324 is a new generation of enterprise-level gigabit high-performance router launched by New H3C Technology Co., Ltd. It is positioned in the cultural industry market such as Internet cafes, singing bars, and digital cinemas.
H3C NER324 has a weak password vulnerability. Attackers can use the vulnerability to log in to the device with the default password to obtain sensitive information.
VAR-202105-1668 | No CVE | Bihaiwei L7 home gateway has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Bihaiwei L7 home gateway is a home gateway launched by Beijing Bihaiwei Technology Co., Ltd.
Bihaiwei L7 home gateway has weak password vulnerability. Attackers can use this vulnerability to log in to the background of the system to obtain sensitive information.
VAR-202105-1662 | No CVE | Hangzhou Guanhang Technology Co., Ltd. GS series enterprise application gateways have weak password vulnerabilities |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Hangzhou Guanhang Technology Co., Ltd. is an innovative intelligent network solution manufacturer. Committed to the development and application of enterprise-level wireless networks, Internet of Things and smart switch products, it is a next-generation enterprise-level wireless, Internet of Things and switch solutions manufacturer.
Hangzhou Guanhang Technology Co., Ltd. GS series enterprise application gateways have a weak password vulnerability. Attackers can use the vulnerability to log in to the system backend to obtain sensitive information.
VAR-202105-1666 | No CVE | Many H3C routers have weak password vulnerabilities |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
ER5100 is a high-performance gigabit router tailored for small and medium-sized enterprises, Internet cafes, schools and other institutions. ER5200G2 is a new generation of enterprise-class gigabit high-performance router. GR5200 is an enterprise-class gigabit router.
Many H3C routers have weak password vulnerabilities, which can be exploited by attackers to obtain sensitive information.
VAR-202105-1663 | No CVE | A stack overflow vulnerability exists in the se*** interface of Tenda 11AC 1200MBPS wireless panel AP (CNVD-2021-25917) |
CVSS V2: 7.2 CVSS V3: - Severity: HIGH |
Shenzhen Jixiang Tengda Technology Co., Ltd. (hereinafter referred to as "Tengda") was founded in 1999. It is a professional supplier of network communication equipment and solutions, as well as a high-tech enterprise integrating R&D, production, supply, sales and service.
The se*** interface of Tenda 11AC 1200MBPS wireless panel AP has a stack overflow vulnerability. Attackers can use this vulnerability to gain control of the server.