VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202106-2201 No CVE Shenzhen Jixiang Tengda Technology Co., Ltd. AC11 has a denial of service vulnerability (CNVD-2021-35780) CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
Tenda AC11 is a wireless router that uses RTOS operating system. Shenzhen Jixiang Tengda Technology Co., Ltd. AC11 has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service attack.
VAR-202106-2202 No CVE Shenzhen Infinova Technology Co., Ltd. INFINOVA NVR has command execution CVSS V2: 7.1
CVSS V3: -
Severity: HIGH
Infinova is the world's leading manufacturer of electronic security products and industry solutions provider. Shenzhen Infinova Technology Co., Ltd. INFINOVA NVR has command execution. Attackers can use this vulnerability to gain control of the server.
VAR-202106-2203 No CVE Shenzhen Jixiang Tengda Technology Co., Ltd. AC11 has a binary vulnerability (CNVD-2021-35779) CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
Tenda AC11 is a wireless router that uses RTOS operating system. Shenzhen Jixiang Tengda Technology Co., Ltd. AC11 has a binary vulnerability, which can be exploited by attackers to cause a denial of service.
VAR-202106-2204 No CVE Tenda wireless router has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Shenzhen Jixiang Tengda Technology Co., Ltd. (hereinafter referred to as "Tengda") was founded in 1999. It is a professional supplier of network communication equipment and solutions, as well as a high-tech enterprise integrating R&D, production, supply, sales and service. Tenda wireless routers have unauthorized access vulnerabilities, which can be exploited by attackers to obtain and modify sensitive information.
VAR-202106-2205 No CVE Shenzhen Infinova Technology Co., Ltd. INFINOVA NVR has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Infinova is the world's leading manufacturer of electronic security products and industry solutions provider. Shenzhen Infinova Technology Co., Ltd. INFINOVA NVR has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2206 No CVE Archer C50 router has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
TP-LINK Technology Co., Ltd. (hereinafter referred to as "TP-LINK") is the world's leading supplier of network communication equipment. The Archer C50 router has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2297 No CVE HP ENVY 5540 All-in-One Printer series printer has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
HP ENVY 5540 All-in-One Printer series printer is an all-in-one printer from Hewlett-Packard Company. The HP ENVY 5540 All-in-One Printer series printer has an unauthorized access vulnerability. Attackers can use this vulnerability to directly access the printer control interface without logging in.
VAR-202106-2299 No CVE Unauthorized access vulnerability exists in HP ENVY 5530 e-All-in-One Printer series CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
The HP ENVY 5530 e-All-in-One Printer series printer is an all-in-one printer from HP Trading (Shanghai) Co., Ltd. The HP ENVY 5530 e-All-in-One Printer series printer has an unauthorized access vulnerability. Attackers can use this vulnerability to directly access the printer control interface without logging in.
VAR-202106-2320 No CVE Unauthorized access vulnerability exists in Lexmark M series CVSS V2: 6.4
CVSS V3: -
Severity: MEDIUM
The Lexmark M series is a product of Lexmark. Lexmark M is an M series printer. Lexmark M series has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2336 No CVE H3C ER G2 series routers have command execution vulnerabilities CVSS V2: 8.3
CVSS V3: -
Severity: HIGH
H3C ER G2 series is a new generation of enterprise-level Gigabit high-performance routers launched by Hangzhou Huasan Communication Technology Co., Ltd. It is positioned in the SMB market for Ethernet/optical/xDSL access, and mainly includes government agencies, Network environment for small and medium-sized enterprises, hotels, schools, hospitals, Internet cafes, etc. H3C ER G2 series routers have a command execution vulnerability, which can be exploited by an attacker to gain control of the server.
VAR-202109-0303 CVE-2021-21570 Dell NetWorker  In  OS  Command injection vulnerability CVSS V2: 4.0
CVSS V3: 4.9
Severity: MEDIUM
Dell NetWorker, versions 18.x and 19.x contain an Information disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and gain access to unauthorized information. Dell EMC NetWorker is a set of unified backup and recovery software from Dell (DELL). The software provides backup and recovery, deduplication, backup reporting, and more
VAR-202109-0302 CVE-2021-21569 Dell NetWorker  Past traversal vulnerability in CVSS V2: 4.0
CVSS V3: 4.9
Severity: MEDIUM
Dell NetWorker, versions 18.x and 19.x contain a Path traversal vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and gain access to unauthorized information. Dell NetWorker is an application of Dell (Dell). Provides Dell's forum discussion function
VAR-202106-2260 No CVE Aitai network management system has command execution vulnerabilities CVSS V2: 7.1
CVSS V3: -
Severity: HIGH
Shanghai Aitai Technology Co., Ltd. is a small and medium-sized network solution provider and service provider in China. Aitai network management system has command execution loopholes. An attacker can use this vulnerability to gain server permissions.
VAR-202106-2261 No CVE Kollmorgen servo drive AKD-P00606-NBPN-000 has a denial of service vulnerability CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
Kollmorgen (Kollmorgen) is the world's leading supplier of motion control systems and accessories. Kollmorgen servo drive AKD-P00606-NBPN-000 has a denial of service vulnerability. Attackers can use this vulnerability to cause the program to crash.
VAR-202106-2262 No CVE H3C ICG 1000 has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
ICG 1000 is a gateway specially launched by H3C for small businesses. H3C ICG 1000 has a weak password vulnerability. Attackers can use this vulnerability to obtain sensitive information.
VAR-202106-2245 No CVE H3C ER G2 series routers have binary vulnerabilities CVSS V2: 4.3
CVSS V3: -
Severity: MEDIUM
H3C ER G2 series is a new generation of enterprise-level Gigabit high-performance routers launched by Hangzhou Huasan Communication Technology Co., Ltd. H3C ER G2 series routers have a binary vulnerability, which can be exploited by an attacker to cause a denial of service.
VAR-202106-2246 No CVE Aitai Technology Network Management System has a command execution vulnerability CVSS V2: 2.1
CVSS V3: -
Severity: LOW
Aitai Technology is a small and medium-sized network solution provider and service provider in China. Aitai Technology's network management system has a command execution vulnerability, which can be exploited by an attacker to gain server control authority.
VAR-202106-2247 No CVE TL-R600VPN has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Pulian Technology Co., Ltd. is a supplier of network communication equipment. TL-R600VPN has a weak password vulnerability. Attackers use this vulnerability to log in to the system background to obtain sensitive information.
VAR-202106-2248 No CVE Shenzhen Hongdian Technology Co., Ltd. H8922 industrial router has an arbitrary file download vulnerability CVSS V2: 2.1
CVSS V3: -
Severity: LOW
The H8922 industrial router uses a high-performance 32-bit MIPS processor and an embedded operating system design. Shenzhen Hongdian Technology Co., Ltd. H8922 industrial router has an arbitrary file download vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2249 No CVE DVA-2800 management platform and DSL-2888A management platform have logic flaws and vulnerabilities CVSS V2: 6.4
CVSS V3: -
Severity: MEDIUM
D-Link Electronic Equipment (Shanghai) Co., Ltd. is a company mainly engaged in network equipment, wireless equipment, switches and other projects. The DVA-2800 management platform and DSL-2888A management platform have logic flaws and vulnerabilities, which can be exploited by attackers to obtain sensitive information.