VARIoT IoT vulnerabilities database
| VAR-202106-2201 | No CVE | Shenzhen Jixiang Tengda Technology Co., Ltd. AC11 has a denial of service vulnerability (CNVD-2021-35780) |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
Tenda AC11 is a wireless router that uses RTOS operating system.
Shenzhen Jixiang Tengda Technology Co., Ltd. AC11 has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service attack.
| VAR-202106-2202 | No CVE | Shenzhen Infinova Technology Co., Ltd. INFINOVA NVR has command execution |
CVSS V2: 7.1 CVSS V3: - Severity: HIGH |
Infinova is the world's leading manufacturer of electronic security products and industry solutions provider.
Shenzhen Infinova Technology Co., Ltd. INFINOVA NVR has command execution. Attackers can use this vulnerability to gain control of the server.
| VAR-202106-2203 | No CVE | Shenzhen Jixiang Tengda Technology Co., Ltd. AC11 has a binary vulnerability (CNVD-2021-35779) |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
Tenda AC11 is a wireless router that uses RTOS operating system.
Shenzhen Jixiang Tengda Technology Co., Ltd. AC11 has a binary vulnerability, which can be exploited by attackers to cause a denial of service.
| VAR-202106-2204 | No CVE | Tenda wireless router has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Shenzhen Jixiang Tengda Technology Co., Ltd. (hereinafter referred to as "Tengda") was founded in 1999. It is a professional supplier of network communication equipment and solutions, as well as a high-tech enterprise integrating R&D, production, supply, sales and service.
Tenda wireless routers have unauthorized access vulnerabilities, which can be exploited by attackers to obtain and modify sensitive information.
| VAR-202106-2205 | No CVE | Shenzhen Infinova Technology Co., Ltd. INFINOVA NVR has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Infinova is the world's leading manufacturer of electronic security products and industry solutions provider.
Shenzhen Infinova Technology Co., Ltd. INFINOVA NVR has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202106-2206 | No CVE | Archer C50 router has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
TP-LINK Technology Co., Ltd. (hereinafter referred to as "TP-LINK") is the world's leading supplier of network communication equipment.
The Archer C50 router has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202106-2297 | No CVE | HP ENVY 5540 All-in-One Printer series printer has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
HP ENVY 5540 All-in-One Printer series printer is an all-in-one printer from Hewlett-Packard Company.
The HP ENVY 5540 All-in-One Printer series printer has an unauthorized access vulnerability. Attackers can use this vulnerability to directly access the printer control interface without logging in.
| VAR-202106-2299 | No CVE | Unauthorized access vulnerability exists in HP ENVY 5530 e-All-in-One Printer series |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
The HP ENVY 5530 e-All-in-One Printer series printer is an all-in-one printer from HP Trading (Shanghai) Co., Ltd.
The HP ENVY 5530 e-All-in-One Printer series printer has an unauthorized access vulnerability. Attackers can use this vulnerability to directly access the printer control interface without logging in.
| VAR-202106-2320 | No CVE | Unauthorized access vulnerability exists in Lexmark M series |
CVSS V2: 6.4 CVSS V3: - Severity: MEDIUM |
The Lexmark M series is a product of Lexmark. Lexmark M is an M series printer.
Lexmark M series has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202106-2336 | No CVE | H3C ER G2 series routers have command execution vulnerabilities |
CVSS V2: 8.3 CVSS V3: - Severity: HIGH |
H3C ER G2 series is a new generation of enterprise-level Gigabit high-performance routers launched by Hangzhou Huasan Communication Technology Co., Ltd. It is positioned in the SMB market for Ethernet/optical/xDSL access, and mainly includes government agencies, Network environment for small and medium-sized enterprises, hotels, schools, hospitals, Internet cafes, etc.
H3C ER G2 series routers have a command execution vulnerability, which can be exploited by an attacker to gain control of the server.
| VAR-202109-0303 | CVE-2021-21570 | Dell NetWorker In OS Command injection vulnerability |
CVSS V2: 4.0 CVSS V3: 4.9 Severity: MEDIUM |
Dell NetWorker, versions 18.x and 19.x contain an Information disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and gain access to unauthorized information. Dell EMC NetWorker is a set of unified backup and recovery software from Dell (DELL). The software provides backup and recovery, deduplication, backup reporting, and more
| VAR-202109-0302 | CVE-2021-21569 | Dell NetWorker Past traversal vulnerability in |
CVSS V2: 4.0 CVSS V3: 4.9 Severity: MEDIUM |
Dell NetWorker, versions 18.x and 19.x contain a Path traversal vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and gain access to unauthorized information. Dell NetWorker is an application of Dell (Dell). Provides Dell's forum discussion function
| VAR-202106-2260 | No CVE | Aitai network management system has command execution vulnerabilities |
CVSS V2: 7.1 CVSS V3: - Severity: HIGH |
Shanghai Aitai Technology Co., Ltd. is a small and medium-sized network solution provider and service provider in China.
Aitai network management system has command execution loopholes. An attacker can use this vulnerability to gain server permissions.
| VAR-202106-2261 | No CVE | Kollmorgen servo drive AKD-P00606-NBPN-000 has a denial of service vulnerability |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
Kollmorgen (Kollmorgen) is the world's leading supplier of motion control systems and accessories.
Kollmorgen servo drive AKD-P00606-NBPN-000 has a denial of service vulnerability. Attackers can use this vulnerability to cause the program to crash.
| VAR-202106-2262 | No CVE | H3C ICG 1000 has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
ICG 1000 is a gateway specially launched by H3C for small businesses.
H3C ICG 1000 has a weak password vulnerability. Attackers can use this vulnerability to obtain sensitive information.
| VAR-202106-2245 | No CVE | H3C ER G2 series routers have binary vulnerabilities |
CVSS V2: 4.3 CVSS V3: - Severity: MEDIUM |
H3C ER G2 series is a new generation of enterprise-level Gigabit high-performance routers launched by Hangzhou Huasan Communication Technology Co., Ltd.
H3C ER G2 series routers have a binary vulnerability, which can be exploited by an attacker to cause a denial of service.
| VAR-202106-2246 | No CVE | Aitai Technology Network Management System has a command execution vulnerability |
CVSS V2: 2.1 CVSS V3: - Severity: LOW |
Aitai Technology is a small and medium-sized network solution provider and service provider in China.
Aitai Technology's network management system has a command execution vulnerability, which can be exploited by an attacker to gain server control authority.
| VAR-202106-2247 | No CVE | TL-R600VPN has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Pulian Technology Co., Ltd. is a supplier of network communication equipment.
TL-R600VPN has a weak password vulnerability. Attackers use this vulnerability to log in to the system background to obtain sensitive information.
| VAR-202106-2248 | No CVE | Shenzhen Hongdian Technology Co., Ltd. H8922 industrial router has an arbitrary file download vulnerability |
CVSS V2: 2.1 CVSS V3: - Severity: LOW |
The H8922 industrial router uses a high-performance 32-bit MIPS processor and an embedded operating system design.
Shenzhen Hongdian Technology Co., Ltd. H8922 industrial router has an arbitrary file download vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202106-2249 | No CVE | DVA-2800 management platform and DSL-2888A management platform have logic flaws and vulnerabilities |
CVSS V2: 6.4 CVSS V3: - Severity: MEDIUM |
D-Link Electronic Equipment (Shanghai) Co., Ltd. is a company mainly engaged in network equipment, wireless equipment, switches and other projects.
The DVA-2800 management platform and DSL-2888A management platform have logic flaws and vulnerabilities, which can be exploited by attackers to obtain sensitive information.