VARIoT IoT vulnerabilities database
| VAR-202106-2095 | No CVE | ZXHN F450A has logic flaw vulnerability |
CVSS V2: 6.4 CVSS V3: - Severity: MEDIUM |
ZTE Corporation is the world's leading provider of integrated communications solutions. The main products include: 2G/3G/4G/5G wireless base station and core network, IMS, fixed network access and bearer, optical network, chip, high-end router, smart switch, government and enterprise network, big data, cloud computing, data center, etc. .
ZXHN F450A has a logic flaw vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202106-2096 | No CVE | Panasonic Electric (China) Co., Ltd. Network Camera WV-SW174W has an unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Matsushita Electric (China) Co., Ltd. is mainly responsible for the sales and after-sales service activities of home appliances, systems, environment, components and other commodities.
Matsushita Electric (China) Co., Ltd. Network Camera WV-SW174W has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202106-2097 | No CVE | Panasonic Electric (China) Co., Ltd. Network Camera WV-SW598 has an unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Matsushita Electric (China) Co., Ltd. is mainly responsible for the sales and after-sales service activities of home appliances, systems, environment, components and other commodities.
Matsushita Electric (China) Co., Ltd. Network Camera WV-SW598 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202106-2098 | No CVE | AXIS V5914 PTZ Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS V5914 PTZ Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202106-2099 | No CVE | AXIS 213 PTZ Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS 213 PTZ Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202106-2100 | No CVE | AXIS 214 PTZ Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS 214 PTZ Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202106-2101 | No CVE | AXIS M3004 Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS M3004 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202106-2102 | No CVE | AXIS 5600+ has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS 5600+ has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202106-2103 | No CVE | Unauthorized access vulnerability exists in HP-LaserJet series of HP Trading (Shanghai) Co., Ltd. |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
The HP-LaserJet series is a printer of Hewlett-Packard Trading (Shanghai) Co., Ltd.
China Hewlett-Packard Co., Ltd. HP-LaserJet series has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202106-2104 | No CVE | 3G/4G Router has information disclosure vulnerabilities |
CVSS V2: 2.1 CVSS V3: - Severity: LOW |
3G/4G Router is a router device of Shenzhen Hongdian Technology Co., Ltd.
3G/4G Router has an information disclosure vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202106-2105 | No CVE | Unauthorized access vulnerability exists in Brickstream 1100 of American Phillie Company |
CVSS V2: 6.4 CVSS V3: - Severity: MEDIUM |
FLIR Systems, Inc. is a company specializing in the design, development, production, marketing and promotion of professional technologies for enhancing situational awareness.
There is an unauthorized access vulnerability in Brickstream 1100, a US-based Philippine company. Attackers can use the vulnerability to obtain sensitive information.
| VAR-202106-2106 | No CVE | Shenzhen Jixiang Tenda Technology Co., Ltd. Tenda wireless router has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Shenzhen Jixiang Tengda Technology Co., Ltd. is a high-tech enterprise integrating independent research and development, production and sales of network equipment.
Shenzhen Jixiang Tenda Technology Co., Ltd. Tenda wireless router has an unauthorized access vulnerability. Attackers can use the vulnerability to obtain sensitive information.
| VAR-202106-2107 | No CVE | Unauthorized access vulnerability exists in Sony (China) Co., Ltd. DATA Projector |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Sony (China) Co., Ltd. was established by Sony Corporation in Beijing in October 1996 as a wholly-owned subsidiary that aims to unify the management and coordination of Sony's business activities in China.
Sony (China) Co., Ltd. DATA Projector has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202106-2109 | No CVE | Unauthorized access vulnerability exists in Enterprise Device Manager |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Avaya, formerly known as the Lucent Technology Enterprise Network Department, is headquartered in New Jersey, USA, and officially became an independent listed company on October 1, 2000.
Enterprise Device Manager has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202106-2110 | No CVE | Unauthorized access vulnerability exists in Extreme ERS3500 |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Extreme, business scope: research, development, and production of advanced voice and data communication network system products, system integration; technical consulting, technical services and technical training for self-produced products.
Extreme ERS3500 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202106-2111 | No CVE | MPEG4 DVR has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
The MPEG Moving Picture Experts Group is an ISO/IEC working group responsible for formulating international standards concerning the compression, decompression, processing and encoding of moving images, audio and their combinations.
MPEG4 DVR has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202106-2319 | No CVE | SuperE32 L601 RTU has a denial of service vulnerability |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
SuperE32 L601 RTU is an integrated RTU of security technology, suitable for SCADA system.
SuperE32 L601 RTU has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service.
| VAR-202106-2321 | No CVE | The TRENDnet webcam has a weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
TRENDnet is one of the world's major data network professional manufacturers.
The TRENDnet webcam has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202106-2323 | No CVE | Yongbo (Xiamen) Electrical Technology Co., Ltd. WinbowPLC has a binary vulnerability |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
Yongbo (Xiamen) Electrical Technology Co., Ltd. was founded in 2010, focusing on overall motion control solutions, and is a professional motion control product and solution provider.
Yongbo (Xiamen) Electrical Technology Co., Ltd. WinbowPLC has a binary vulnerability, which can be exploited by attackers to cause a denial of service.
| VAR-202106-2339 | No CVE | Unauthorized access vulnerability exists in the operation and maintenance audit system of New H3C Technology Co., Ltd. |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
New H3C Technology Co., Ltd. is committed to becoming the most reliable partner for customers' business innovation and digital transformation. The main products are routers, big data, switches, Internet of Things, cloud computing, servers, etc.
The operation and maintenance audit system of New H3C Technology Co., Ltd. has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.