VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202107-1695 No CVE Ruijie Networks Co., Ltd. EG Easy Gateway has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Ruijie Networks is a professional network manufacturer with a full range of network equipment product lines and solutions including switches, routers, software, security firewalls, wireless products, storage, etc. Ruijie Networks Co., Ltd. EG Easy Gateway has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1697 No CVE Command execution vulnerability exists in EG application control engine CVSS V2: 7.1
CVSS V3: -
Severity: HIGH
Ruijie Networks EG application control engine is a multi-service integrated gateway product launched by Ruijie Networks to solve the current network export problems. The EG application control engine has a command execution vulnerability, which can be exploited by an attacker to gain server control authority.
VAR-202107-1699 No CVE ASUS RT-N56U has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
ASUS RT-N56U is a router device. ASUS RT-N56U has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1704 No CVE ASUS RT-N12 has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
ASUS RT-N12 is a router device. ASUS RT-N12 has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1900 No CVE Binary vulnerabilities exist in picoTCP and picoTCP-NG CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
picoTCP is a small footprint and modular TCP/IP stack designed for embedded systems and the Internet of Things. There are binary vulnerabilities in picoTCP and picoTCP-NG, which can be exploited by attackers to gain server control authority.
VAR-202107-1902 No CVE A command execution vulnerability exists in the H2 console of Hangzhou Hikvision Digital Technology Co., Ltd. CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
Hangzhou Hikvision Digital Technology Co., Ltd. is a video-centric IoT solution provider, providing comprehensive security, smart business and big data services. The H2 console of Hangzhou Hikvision Digital Technology Co., Ltd. has a command execution vulnerability. Attackers can use the vulnerability to gain control of the server.
VAR-202107-1907 No CVE Unauthorized access vulnerability exists in SecPath ACG1000 of New H3C Technology Co., Ltd. CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
SecPath ACG1000 is a new generation of virtualized application control gateway specially designed for NFV and cloud computing environment. New H3C Technology Co., Ltd. SecPath ACG1000 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1701 No CVE Ruijie Networks EG Easy Gateway has a command execution vulnerability CVSS V2: 7.1
CVSS V3: -
Severity: HIGH
Ruijie Networks is a professional network manufacturer with a full range of network equipment product lines and solutions including switches, routers, software, security firewalls, wireless products, storage, etc. Ruijie Networks EG Easy Gateway has a command execution vulnerability. Attackers can use this vulnerability to gain control of the server.
VAR-202107-1702 No CVE Chengdu Zhifeng Network Technology Co., Ltd. enterprise-level flow control cloud router has logic flaws and vulnerabilities CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Chengdu Zhifeng Technology Co., Ltd. was established in October 2016. It is an emerging high-tech company integrating R&D, production and sales. The enterprise-level flow control cloud router of Chengdu Zhifeng Technology Co., Ltd. has a logic flaw vulnerability, which can be used by attackers to obtain sensitive information.
VAR-202107-1703 No CVE Ruijie Networks Co., Ltd. RG-ISG has a command execution vulnerability CVSS V2: 7.1
CVSS V3: -
Severity: HIGH
Ruijie Networks is a professional network manufacturer with a full range of network equipment product lines and solutions including switches, routers, software, security firewalls, wireless products, storage, etc. Ruijie Networks Co., Ltd. RG-ISG has a command execution vulnerability. Attackers can use this vulnerability to gain control of the server.
VAR-202107-1788 No CVE Ruijie Networks Co., Ltd. RG-MA1220 has a weak password vulnerability (CNVD-2021-40135) CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Ruijie Networks Co., Ltd. is a company mainly engaged in information system integration services; Internet virtual private network services; Internet management services. Ruijie Networks Co., Ltd. RG-MA1220 has a weak password vulnerability. Attackers can use the vulnerability to obtain sensitive information.
VAR-202107-1790 No CVE Ruijie NBR router has a command execution vulnerability CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
Ruijie Networks is a professional network manufacturer with a full range of network equipment product lines and solutions including switches, routers, software, security firewalls, wireless products, storage, etc. Ruijie NBR router has a command execution vulnerability. Attackers can use this vulnerability to gain control of the server.
VAR-202107-1827 No CVE Vivo mobile phone interface has unauthorized access vulnerability CVSS V2: 6.4
CVSS V3: -
Severity: MEDIUM
The business scope of Guangdong Tianchen Network Technology Co., Ltd. includes: computer software and hardware technology development and sales; Internet and mobile Internet software products technology development and sales; mobile communication equipment and software design, etc. Vivo mobile phone interface has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1829 No CVE Information disclosure vulnerability exists in LCAD03VLNOD series CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Belkin Corporation is a global leader in peripheral products, providing users of computer, digital and mobile products with innovative connection technologies. The LCAD03VLNOD series has an information disclosure vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1831 No CVE Information disclosure vulnerability exists in LCAD03FLN series CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Belkin Corporation is a global leader in peripheral products, providing users of computer, digital and mobile products with innovative connection technologies. The LCAD03FLN series has an information disclosure vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1898 No CVE Shandong Kede Electronics Co., Ltd. has an unauthorized access vulnerability in the IoT smart water meter monitoring platform CVSS V2: 6.4
CVSS V3: -
Severity: MEDIUM
The IoT smart water meter monitoring platform is a smart water meter monitoring platform developed by Shandong Kede Electronics Co., Ltd. It has functions such as water account opening, payment management, data reporting and water meter management. Shandong Kede Electronics Co., Ltd. has an unauthorized access vulnerability in the IoT smart water meter monitoring platform. Attackers can use this vulnerability to read user information without authorization, and perform unauthorized operations on water charge recharge, user management and other related functions.
VAR-202107-1899 No CVE Shenzhen Wanwang Broadcom Technology Co., Ltd. Holographic AI Network Operation and Maintenance Platform Has Weak Password Vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Shenzhen Wanwang Broadcom Investment Management Limited Partnership (Limited Partnership) (hereinafter referred to as TG Wanwang Broadcom) is committed to the development and application of network communication products and IoT security management and control platforms. It is the next generation of weak current intelligent network solutions and the Internet of Things Security solution manufacturer. The holographic AI network operation and maintenance platform of Shenzhen Wanwang Broadcom Technology Co., Ltd. has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-0508 CVE-2020-4938 IBM MQ Appliance Cross-site request forgery vulnerability CVSS V2: 6.8
CVSS V3: 8.8
Severity: HIGH
IBM MQ Appliance 9.1 and 9.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 191815
VAR-202107-1478 CVE-2021-36371 Emissary-Ingress trust management issue vulnerability CVSS V2: 4.3
CVSS V3: 3.7
Severity: LOW
Emissary-Ingress (formerly Ambassador API Gateway) through 1.13.9 allows attackers to bypass client certificate requirements (i.e., mTLS cert_required) on backend upstreams when more than one TLSContext is defined and at least one configuration exists that does not require client certificate authentication. The attacker must send an SNI specifying an unprotected backend and an HTTP Host header specifying a protected backend. (2.x versions are unaffected. 1.x versions are unaffected with certain configuration settings involving prune_unreachable_routes and a wildcard Host resource.). Emissary-Ingress ( Old Ambassador API Gateway) Contains a certificate validation vulnerability.Information may be tampered with. Emissary-Ingress is an open source Kubernetes native API gateway for microservices built by Envoy proxy
VAR-202107-1705 No CVE Beijing Xingwang Ruijie Network Technology Co., Ltd. WS5302 has an arbitrary file download vulnerability CVSS V2: 4.0
CVSS V3: -
Severity: MEDIUM
WS5302 is a wireless controller. Beijing Starnet Ruijie Networks Technology Co., Ltd. WS5302 has an arbitrary file download vulnerability. Attackers can use this vulnerability to download bin files and obtain sensitive information.