VARIoT IoT vulnerabilities database
| VAR-202107-1709 | No CVE | Any file download vulnerability exists in the next-generation firewall security gateway of Feiyuxing |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Chengdu Feiyuxing Technology Co., Ltd. is one of the few local enterprises in the industry with independent intellectual property rights and independent research and development capabilities. It is a high-tech enterprise focusing on product innovation and research in the data communication industry and the Internet of Things industry.
There is an arbitrary file download vulnerability in the Feiyuxing next-generation firewall security gateway, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1710 | No CVE | Any file download vulnerability exists in the multi-service security gateway of Shanghai Huayi Technology Group Co., Ltd. |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Shanghai Huayi Technology Group Co., Ltd. is a company mainly engaged in the research and development, manufacturing of test benches in the field of automotive powertrain and the provision of related technical services.
An arbitrary file download vulnerability exists in the multi-service security gateway of Shanghai Huayi Technology Group Co., Ltd., which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1711 | No CVE | Rascomda Technology Development Co., Ltd. security router has an arbitrary file download vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Raisecomda Technology Development Co., Ltd. focuses on the field of optical fiber broadband access, and is committed to the integration of optical fiber technology, Ethernet technology and broadband access technology.
The security router of Rascomda Technology Development Co., Ltd. has an arbitrary file download vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1712 | No CVE | Any file download vulnerability exists in Hikvision's secure access gateway |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Hangzhou Hikvision Digital Technology Co., Ltd. is a leading provider of security products and industry solutions.
The Hikvision secure access gateway has an arbitrary file download vulnerability. Attackers can use this vulnerability to obtain sensitive information.
| VAR-202107-1713 | No CVE | Hikvision security access gateway has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Hangzhou Hikvision Digital Technology Co., Ltd. is a leading provider of security products and industry solutions.
Hikvision security access gateway has weak password vulnerability. Attackers can use this vulnerability to log in to the background to obtain sensitive information.
| VAR-202107-1714 | No CVE | Xingwang Smart SVG6000 series voice gateways have weak password vulnerabilities |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
As the core business unit of StarNet Ruijie for smart communications, StarNet Wisdom is a leading provider of converged communication solutions in China.
Starnet Smart SVG6000 series voice gateways have weak password vulnerabilities. The attacker uses a weak password to log in to the background to obtain sensitive information.
| VAR-202107-1715 | CVE-2025-34044 | WIFISKY 7-layer flow control router has command execution vulnerabilities |
CVSS V2: 7.1 CVSS V3: - Severity: Critical |
A remote command injection vulnerability exists in the confirm.php interface of the WIFISKY 7-layer Flow Control Router via a specially-crafted HTTP GET request to the t parameter. Insufficient input validation allows unauthenticated attackers to execute arbitrary OS commands. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-25 UTC. Shenzhen Airspace Technology Co., Ltd. ("Airspace Technology" for short) is a network communication equipment supplier rooted in Shenzhen and radiating the world. An attacker can use this vulnerability to gain control of the server
| VAR-202107-1716 | No CVE | Huawei HG659 has an arbitrary file reading vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Huawei HG659 is a home gateway.
Huawei HG659 has arbitrary file reading vulnerabilities. Attackers can use the vulnerabilities to obtain sensitive information.
| VAR-202107-1870 | No CVE | Unauthorized access vulnerability exists in Axis 2120 Network Camera |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
Axis 2120 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1871 | No CVE | AXIS M3114 Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS M3114 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1872 | No CVE | AXIS M5014 Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS M5014 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1873 | No CVE | AXIS M3113 Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS M3113 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1874 | No CVE | AXIS M3025 Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS M3025 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1875 | No CVE | AXIS P5534 Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS P5534 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1876 | No CVE | AXIS P3344 Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS P3344 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1877 | No CVE | AXIS P1353 Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS P1353 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1878 | No CVE | Unauthorized access vulnerability exists in Cisco IP Phone CP-8865 |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Cisco IP Phone CP-8865 is an enterprise-class IP phone.
Cisco IP Phone CP-8865 has an unauthorized access vulnerability. Attackers can use vulnerabilities to obtain sensitive information.
| VAR-202107-1879 | No CVE | AXIS 2130R PTZ Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS 2130R PTZ Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1880 | No CVE | Unauthorized access vulnerability exists in AXIS M7014 Video Encoder |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS M7014 Video Encoder has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1881 | No CVE | Unauthorized access vulnerability exists in AXIS 206M Network Camera |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS 206M Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.