VARIoT IoT vulnerabilities database
| VAR-202106-2330 | No CVE | Zero Vision Technology (Shanghai) Co., Ltd. H5S video platform has an information disclosure vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Zero Vision Technology serves customers with video technology and is committed to simplifying the development of Internet of Things video.
Zero Vision Technology (Shanghai) Co., Ltd. H5S video platform has an information disclosure vulnerability. Attackers can use the vulnerability to obtain sensitive information.
| VAR-202106-0971 | CVE-2021-27388 | plural SINAMICS Input validation vulnerabilities in medium voltage routerable products |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
SINAMICS medium voltage routable products are affected by a vulnerability in the Sm@rtServer component for remote access that could allow an unauthenticated attacker to cause a denial-of-service condition, and/or execution of limited configuration modifications and/or execution of limited control commands on the SINAMICS Medium Voltage Products, Remote Access (SINAMICS SL150: All versions, SINAMICS SM150: All versions, SINAMICS SM150i: All versions). SINAMICS SL150 , SINAMICS SM150 , SINAMICS SM150i Is vulnerable to input validation.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state
| VAR-202106-2181 | No CVE | AXIS 2420 Network Camera has unauthorized access vulnerability |
CVSS V2: 6.4 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS 2420 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202106-2189 | No CVE | The intelligent transportation terminal management equipment of Zhejiang Dahua Technology Co., Ltd. has logic defects and vulnerabilities |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Zhejiang Dahua Technology Co., Ltd. is a smart IoT solution provider and operation service provider with video as the core.
The intelligent transportation terminal management equipment of Zhejiang Dahua Technology Co., Ltd. has a logic flaw vulnerability, which can be used by attackers to obtain sensitive information.
| VAR-202106-2190 | No CVE | The camera of Zhejiang Dahua Technology Co., Ltd. has logic flaws and vulnerabilities |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Zhejiang Dahua Technology Co., Ltd. is a leading monitoring product supplier and solution service provider.
The camera of Zhejiang Dahua Technology Co., Ltd. has a logic flaw vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202106-2191 | No CVE | AXIS 209MFD Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS 209MFD Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202106-2192 | No CVE | AXIS 225FD Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS 225FD Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202106-2193 | No CVE | AXIS M1125 Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS M1125 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202106-2194 | No CVE | AXIS M1124 Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS M1124 Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202106-2195 | No CVE | Unauthorized access vulnerability exists in HP Officejet 5740 e-All-in-One Printer series |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
HP Officejet 5740 e-All-in-One Printer series is an all-in-one printer from HP Trading (Shanghai) Co., Ltd.
The HP Officejet 5740 e-All-in-One Printer series has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202106-2196 | No CVE | Unauthorized access vulnerability exists in HP Officejet 4630 e-All-in-One Printer series |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
HP Officejet 4630 e-All-in-One Printer series is an all-in-one printer from HP Trading (Shanghai) Co., Ltd.
The HP Officejet 4630 e-All-in-One Printer series has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202106-2197 | No CVE | H3C SecPath U200-M has SQL injection vulnerability |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
H3C SecPath U200-M is a new generation of UTM (United Threat Management) equipment designed by H3C for small and medium-sized enterprises/branches.
Xin H3C SecPath U200-M has a SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information in the database.
| VAR-202106-2198 | No CVE | Shenzhen Jixiang Tengda Technology Co., Ltd. AC11 has a denial of service vulnerability (CNVD-2021-35781) |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
Tenda AC11 is a wireless router that uses RTOS operating system.
Shenzhen Jixiang Tengda Technology Co., Ltd. AC11 has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service attack.
| VAR-202106-2199 | No CVE | Shenzhen Jixiang Tengda Technology Co., Ltd. AC11 has a denial of service vulnerability (CNVD-2021-35782) |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
Tenda AC11 is a wireless router that uses RTOS operating system.
Shenzhen Jixiang Tengda Technology Co., Ltd. AC11 has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service attack.
| VAR-202106-2200 | No CVE | Shenzhen Jixiang Tengda Technology Co., Ltd. AC11 has a denial of service vulnerability (CNVD-2021-35783) |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
Tenda AC11 is a wireless router that uses RTOS operating system.
Shenzhen Jixiang Tengda Technology Co., Ltd. AC11 has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service attack.
| VAR-202106-2201 | No CVE | Shenzhen Jixiang Tengda Technology Co., Ltd. AC11 has a denial of service vulnerability (CNVD-2021-35780) |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
Tenda AC11 is a wireless router that uses RTOS operating system.
Shenzhen Jixiang Tengda Technology Co., Ltd. AC11 has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service attack.
| VAR-202106-2202 | No CVE | Shenzhen Infinova Technology Co., Ltd. INFINOVA NVR has command execution |
CVSS V2: 7.1 CVSS V3: - Severity: HIGH |
Infinova is the world's leading manufacturer of electronic security products and industry solutions provider.
Shenzhen Infinova Technology Co., Ltd. INFINOVA NVR has command execution. Attackers can use this vulnerability to gain control of the server.
| VAR-202106-2203 | No CVE | Shenzhen Jixiang Tengda Technology Co., Ltd. AC11 has a binary vulnerability (CNVD-2021-35779) |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
Tenda AC11 is a wireless router that uses RTOS operating system.
Shenzhen Jixiang Tengda Technology Co., Ltd. AC11 has a binary vulnerability, which can be exploited by attackers to cause a denial of service.
| VAR-202106-2204 | No CVE | Tenda wireless router has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Shenzhen Jixiang Tengda Technology Co., Ltd. (hereinafter referred to as "Tengda") was founded in 1999. It is a professional supplier of network communication equipment and solutions, as well as a high-tech enterprise integrating R&D, production, supply, sales and service.
Tenda wireless routers have unauthorized access vulnerabilities, which can be exploited by attackers to obtain and modify sensitive information.
| VAR-202106-2205 | No CVE | Shenzhen Infinova Technology Co., Ltd. INFINOVA NVR has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Infinova is the world's leading manufacturer of electronic security products and industry solutions provider.
Shenzhen Infinova Technology Co., Ltd. INFINOVA NVR has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.