VARIoT IoT vulnerabilities database

VAR-202106-1212 | CVE-2021-33528 | plural Weidmueller Industrial WLAN Vulnerability in improper compliance with coding standards on devices |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
In Weidmueller Industrial WLAN devices in multiple versions an exploitable privilege escalation vulnerability exists in the iw_console functionality. A specially crafted menu selection string can cause an escape from the restricted console, resulting in system access as the root user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability. plural Weidmueller Industrial WLAN Devices contain vulnerabilities to improper compliance with coding standards.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Weidmueller Industrial WLAN devices is an industrial control WIAN of Weidmueller company in Germany
VAR-202106-1216 | CVE-2021-33532 | plural Weidmueller Industrial WLAN In the device OS Command injection vulnerability |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A specially crafted diagnostic script file name can cause user input to be reflected in a subsequent iw_system call, resulting in remote control over the device. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability. Weidmueller Industrial WLAN devices is an industrial control WIAN of Weidmueller company in Germany
VAR-202106-2134 | No CVE | Shenzhen UTP Technology Co., Ltd. UTP-R3050-5GP has a SQL injection vulnerability |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
Established in 2005, UTEPO is an industrial communication and intelligent Internet of Things solution provider with "Internet and Electricity Speed Connection" technology as the core. Based on technological innovation, it is a smart park, smart security, smart city, Provide smart IoT solutions in fields such as smart agriculture and smart manufacturing.
Shenzhen UTP Technology Co., Ltd. UTP-R3050-5GP has a SQL injection vulnerability. Attackers can use the vulnerability to obtain sensitive information in the database.
VAR-202106-2135 | No CVE | D-Link DIR-809 has a denial of service vulnerability (CNVD-2021-36511) |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
D-Link DIR-809 is a wireless router using RTOS.
D-Link DIR-809 has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service attack.
VAR-202106-2136 | No CVE | D-Link DIR-809 has a denial of service vulnerability (CNVD-2021-36512) |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
D-Link DIR-809 is a wireless router using RTOS.
D-Link DIR-809 has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service attack.
VAR-202106-2137 | No CVE | D-Link DIR-809 has a denial of service vulnerability (CNVD-2021-36513) |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
D-Link DIR-809 is a wireless router using RTOS.
D-Link DIR-809 has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service attack.
VAR-202106-2138 | No CVE | D-Link DIR-809 has a denial of service vulnerability (CNVD-2021-36510) |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
D-Link DIR-809 is a wireless router using RTOS.
D-Link DIR-809 has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service attack.
VAR-202106-2139 | No CVE | D-Link DIR-809 has a stack overflow vulnerability |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
D-Link DIR-809 is a wireless router, using RTOS system.
D-Link DIR-809 has a stack overflow vulnerability, which can be exploited by an attacker to cause a denial of service attack.
VAR-202106-2140 | No CVE | D-Link DIR-809 has a denial of service vulnerability |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
D-Link DIR-809 is a wireless router using RTOS.
D-Link DIR-809 has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service attack.
VAR-202106-2141 | No CVE | Bihaiwei L7 cloud router wireless operation version has command execution vulnerabilities |
CVSS V2: 10.0 CVSS V3: - Severity: HIGH |
Bihaiwei L7 Cloud Router is a router launched by Beijing Bihaiwei Technology Co., Ltd.
Bihaiwei L7 cloud router wireless operation version has command execution vulnerabilities. An attacker can use this vulnerability to gain control of the server.
VAR-202106-2142 | No CVE | Schneider Electric (China) Co., Ltd. power monitoring PowerLogic ION7650 has unauthorized vulnerabilities |
CVSS V2: 6.4 CVSS V3: - Severity: MEDIUM |
Schneider Electric (China) Co., Ltd. is a company whose main business includes electric power, industrial automation, infrastructure, energy efficiency, energy, building automation and security electronics, data centers and smart living spaces.
Schneider Electric (China) Co., Ltd. power monitoring PowerLogic ION7650 has an unauthorized vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2143 | No CVE | Bihaiwei L7 cloud router wireless operation version has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Bihaiwei L7 Cloud Router is a router launched by Beijing Bihaiwei Technology Co., Ltd.
Bihaiwei L7 cloud router wireless operation version has weak password vulnerability. Attackers can use this vulnerability to log in to the system backend to obtain sensitive information
VAR-202106-2144 | No CVE | NETGEAR WNR2020 router has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
NETGEAR WNR2020 router is a wireless router device.
The NETGEAR WNR2020 router has a weak password vulnerability. Attackers can use this vulnerability to control the device, obtain sensitive information and perform unauthorized operations.
VAR-202106-2145 | No CVE | AXIS XIS Q1602 Network Camera has unauthorized access vulnerability |
CVSS V2: 6.4 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions. It is the global market leader in network video, driving the transition from analog to digital video surveillance. Axis' monitoring products and solutions are based on an open and innovative technology platform, dedicated to security monitoring and remote monitoring.
AXIS XIS Q1602 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2146 | No CVE | AXIS Q1604 Network Camera has unauthorized access vulnerability |
CVSS V2: 6.4 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions. It is the global market leader in network video, driving the transition from analog to digital video surveillance. Axis' monitoring products and solutions are based on an open and innovative technology platform, dedicated to security monitoring and remote monitoring.
AXIS Q1604 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2147 | No CVE | AXIS Q1755 Network Camera has unauthorized access vulnerability |
CVSS V2: 6.4 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions. It is the global market leader in network video, driving the transition from analog to digital video surveillance. Axis' monitoring products and solutions are based on an open and innovative technology platform, dedicated to security monitoring and remote monitoring.
AXIS Q1755 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2148 | No CVE | Finetree 5MP Network Camera has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
5MP Network Camera is a camera product.
Finetree 5MP Network Camera has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2149 | No CVE | 5MP Network Camera has logic flaw vulnerability |
CVSS V2: 6.4 CVSS V3: - Severity: MEDIUM |
5MP Network Camer is a network camera.
5MP Network Camera has a logic flaw vulnerability. Attackers can use this vulnerability to add users arbitrarily.
VAR-202106-2150 | No CVE | NETGEAR WNR1000v3 router has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
NETGEAR WNR1000v3 router is a wireless router device.
The NETGEAR WNR1000v3 router has a weak password vulnerability. Attackers can use this vulnerability to control the device, obtain sensitive information and perform unauthorized operations.
VAR-202106-2151 | No CVE | NETGEAR WNDR3700v4 router has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
The NETGEAR WNDR3700v4 router is a wireless router device.
The NETGEAR WNDR3700v4 router has a weak password vulnerability. Attackers can use this vulnerability to control the device, obtain sensitive information and perform unauthorized operations.