VARIoT IoT vulnerabilities database
| VAR-202107-1695 | No CVE | Ruijie Networks Co., Ltd. EG Easy Gateway has a weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Ruijie Networks is a professional network manufacturer with a full range of network equipment product lines and solutions including switches, routers, software, security firewalls, wireless products, storage, etc.
Ruijie Networks Co., Ltd. EG Easy Gateway has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1697 | No CVE | Command execution vulnerability exists in EG application control engine |
CVSS V2: 7.1 CVSS V3: - Severity: HIGH |
Ruijie Networks EG application control engine is a multi-service integrated gateway product launched by Ruijie Networks to solve the current network export problems.
The EG application control engine has a command execution vulnerability, which can be exploited by an attacker to gain server control authority.
| VAR-202107-1699 | No CVE | ASUS RT-N56U has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
ASUS RT-N56U is a router device.
ASUS RT-N56U has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1704 | No CVE | ASUS RT-N12 has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
ASUS RT-N12 is a router device.
ASUS RT-N12 has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1900 | No CVE | Binary vulnerabilities exist in picoTCP and picoTCP-NG |
CVSS V2: 10.0 CVSS V3: - Severity: HIGH |
picoTCP is a small footprint and modular TCP/IP stack designed for embedded systems and the Internet of Things.
There are binary vulnerabilities in picoTCP and picoTCP-NG, which can be exploited by attackers to gain server control authority.
| VAR-202107-1902 | No CVE | A command execution vulnerability exists in the H2 console of Hangzhou Hikvision Digital Technology Co., Ltd. |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
Hangzhou Hikvision Digital Technology Co., Ltd. is a video-centric IoT solution provider, providing comprehensive security, smart business and big data services.
The H2 console of Hangzhou Hikvision Digital Technology Co., Ltd. has a command execution vulnerability. Attackers can use the vulnerability to gain control of the server.
| VAR-202107-1907 | No CVE | Unauthorized access vulnerability exists in SecPath ACG1000 of New H3C Technology Co., Ltd. |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
SecPath ACG1000 is a new generation of virtualized application control gateway specially designed for NFV and cloud computing environment.
New H3C Technology Co., Ltd. SecPath ACG1000 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1701 | No CVE | Ruijie Networks EG Easy Gateway has a command execution vulnerability |
CVSS V2: 7.1 CVSS V3: - Severity: HIGH |
Ruijie Networks is a professional network manufacturer with a full range of network equipment product lines and solutions including switches, routers, software, security firewalls, wireless products, storage, etc.
Ruijie Networks EG Easy Gateway has a command execution vulnerability. Attackers can use this vulnerability to gain control of the server.
| VAR-202107-1702 | No CVE | Chengdu Zhifeng Network Technology Co., Ltd. enterprise-level flow control cloud router has logic flaws and vulnerabilities |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Chengdu Zhifeng Technology Co., Ltd. was established in October 2016. It is an emerging high-tech company integrating R&D, production and sales.
The enterprise-level flow control cloud router of Chengdu Zhifeng Technology Co., Ltd. has a logic flaw vulnerability, which can be used by attackers to obtain sensitive information.
| VAR-202107-1703 | No CVE | Ruijie Networks Co., Ltd. RG-ISG has a command execution vulnerability |
CVSS V2: 7.1 CVSS V3: - Severity: HIGH |
Ruijie Networks is a professional network manufacturer with a full range of network equipment product lines and solutions including switches, routers, software, security firewalls, wireless products, storage, etc.
Ruijie Networks Co., Ltd. RG-ISG has a command execution vulnerability. Attackers can use this vulnerability to gain control of the server.
| VAR-202107-1788 | No CVE | Ruijie Networks Co., Ltd. RG-MA1220 has a weak password vulnerability (CNVD-2021-40135) |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Ruijie Networks Co., Ltd. is a company mainly engaged in information system integration services; Internet virtual private network services; Internet management services.
Ruijie Networks Co., Ltd. RG-MA1220 has a weak password vulnerability. Attackers can use the vulnerability to obtain sensitive information.
| VAR-202107-1790 | No CVE | Ruijie NBR router has a command execution vulnerability |
CVSS V2: 10.0 CVSS V3: - Severity: HIGH |
Ruijie Networks is a professional network manufacturer with a full range of network equipment product lines and solutions including switches, routers, software, security firewalls, wireless products, storage, etc.
Ruijie NBR router has a command execution vulnerability. Attackers can use this vulnerability to gain control of the server.
| VAR-202107-1827 | No CVE | Vivo mobile phone interface has unauthorized access vulnerability |
CVSS V2: 6.4 CVSS V3: - Severity: MEDIUM |
The business scope of Guangdong Tianchen Network Technology Co., Ltd. includes: computer software and hardware technology development and sales; Internet and mobile Internet software products technology development and sales; mobile communication equipment and software design, etc.
Vivo mobile phone interface has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1829 | No CVE | Information disclosure vulnerability exists in LCAD03VLNOD series |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Belkin Corporation is a global leader in peripheral products, providing users of computer, digital and mobile products with innovative connection technologies.
The LCAD03VLNOD series has an information disclosure vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1831 | No CVE | Information disclosure vulnerability exists in LCAD03FLN series |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Belkin Corporation is a global leader in peripheral products, providing users of computer, digital and mobile products with innovative connection technologies.
The LCAD03FLN series has an information disclosure vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1898 | No CVE | Shandong Kede Electronics Co., Ltd. has an unauthorized access vulnerability in the IoT smart water meter monitoring platform |
CVSS V2: 6.4 CVSS V3: - Severity: MEDIUM |
The IoT smart water meter monitoring platform is a smart water meter monitoring platform developed by Shandong Kede Electronics Co., Ltd. It has functions such as water account opening, payment management, data reporting and water meter management.
Shandong Kede Electronics Co., Ltd. has an unauthorized access vulnerability in the IoT smart water meter monitoring platform. Attackers can use this vulnerability to read user information without authorization, and perform unauthorized operations on water charge recharge, user management and other related functions.
| VAR-202107-1899 | No CVE | Shenzhen Wanwang Broadcom Technology Co., Ltd. Holographic AI Network Operation and Maintenance Platform Has Weak Password Vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Shenzhen Wanwang Broadcom Investment Management Limited Partnership (Limited Partnership) (hereinafter referred to as TG Wanwang Broadcom) is committed to the development and application of network communication products and IoT security management and control platforms. It is the next generation of weak current intelligent network solutions and the Internet of Things Security solution manufacturer.
The holographic AI network operation and maintenance platform of Shenzhen Wanwang Broadcom Technology Co., Ltd. has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-0508 | CVE-2020-4938 | IBM MQ Appliance Cross-site request forgery vulnerability |
CVSS V2: 6.8 CVSS V3: 8.8 Severity: HIGH |
IBM MQ Appliance 9.1 and 9.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 191815
| VAR-202107-1478 | CVE-2021-36371 | Emissary-Ingress trust management issue vulnerability |
CVSS V2: 4.3 CVSS V3: 3.7 Severity: LOW |
Emissary-Ingress (formerly Ambassador API Gateway) through 1.13.9 allows attackers to bypass client certificate requirements (i.e., mTLS cert_required) on backend upstreams when more than one TLSContext is defined and at least one configuration exists that does not require client certificate authentication. The attacker must send an SNI specifying an unprotected backend and an HTTP Host header specifying a protected backend. (2.x versions are unaffected. 1.x versions are unaffected with certain configuration settings involving prune_unreachable_routes and a wildcard Host resource.). Emissary-Ingress ( Old Ambassador API Gateway) Contains a certificate validation vulnerability.Information may be tampered with. Emissary-Ingress is an open source Kubernetes native API gateway for microservices built by Envoy proxy
| VAR-202107-1705 | No CVE | Beijing Xingwang Ruijie Network Technology Co., Ltd. WS5302 has an arbitrary file download vulnerability |
CVSS V2: 4.0 CVSS V3: - Severity: MEDIUM |
WS5302 is a wireless controller.
Beijing Starnet Ruijie Networks Technology Co., Ltd. WS5302 has an arbitrary file download vulnerability. Attackers can use this vulnerability to download bin files and obtain sensitive information.