VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202105-1665 No CVE Feiyuxing Technology Development Co., Ltd. Volans has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Chengdu Feiyuxing Technology Co., Ltd. was established in 2002 as a high-tech enterprise focusing on product innovation and research and development in the data communication industry and the Internet of Things industry. Volans of Feiyuxing Technology Development Co., Ltd. has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202105-1669 No CVE Universal Technology Co., Ltd. USG2130 has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
TL-ER2220G is a dual-core multi-WAN port gigabit enterprise VPN router from Prolink Technology Co., Ltd. Universal Technology Co., Ltd. USG2130 has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202105-1671 No CVE H3C ER3200 router has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
ER3200 is a high-performance router launched by H3C. The H3C ER3200 router has a weak password vulnerability. Attackers use this vulnerability to log in to the background of the system to obtain sensitive information.
VAR-202105-1672 No CVE Multiple Huawei products have weak password vulnerabilities CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Secoway USG2160BSR is a firewall of Huawei Technologies Co., Ltd., Huawei SRG3230 is a gateway, and Huawei SRG1220 is a router of Huawei Technologies Co., Ltd. Many Huawei products have weak password vulnerabilities, which can be exploited by attackers to obtain sensitive information.
VAR-202105-1673 No CVE Many products of New H3C Technology Co., Ltd. have weak password vulnerabilities CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
ER5100 is a high-performance gigabit downstream router. ER5200G2 is a new generation of enterprise-class gigabit high-performance router. GR5200 is a new generation of high-performance enterprise-class routers. Many products of New H3C Technology Co., Ltd. have weak password vulnerabilities, which can be exploited by attackers to obtain sensitive information.
VAR-202105-1674 No CVE HUAWEI SRG1220w has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
SRG1220w is a router. HUAWEI SRG1220w has a weak password vulnerability. Attackers can use this vulnerability to obtain sensitive information.
VAR-202105-1675 No CVE HUAWEI SRG2210 has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
SRG2210 is a router. HUAWEI SRG2210 has a weak password vulnerability. Attackers can use this vulnerability to obtain sensitive information.
VAR-202105-1677 No CVE H3C ER6300 router has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
ER6300 is a high-performance all-gigabit dedicated router for Internet cafes launched by H3C. The H3C ER6300 router has a weak password vulnerability. Attackers can use this vulnerability to log in to the router background to obtain sensitive information.
VAR-202105-1127 CVE-2021-31756 Tenda AC11  Out-of-bounds write vulnerability in device CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /gofrom/setwanType allows attackers to execute arbitrary code on the system via a crafted post request. This occurs when input vector controlled by malicious attack get copied to the stack variable. Tenda AC11 The device contains an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Tenda AC11 is an AC1200 dual-band Gigabit WiFi router
VAR-202105-1126 CVE-2021-31755 Tenda AC11  Out-of-bounds write vulnerability in device CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request. Tenda AC11 The device contains an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Tenda AC11 is an AC1200 dual-band Gigabit WiFi router
VAR-202105-1128 CVE-2021-31757 Tenda AC11  Out-of-bounds write vulnerability in device CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setVLAN allows attackers to execute arbitrary code on the system via a crafted post request. Tenda AC11 The device contains an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Tenda AC11 is an AC1200 dual-band Gigabit WiFi router
VAR-202105-1129 CVE-2021-31758 Tenda AC11  Out-of-bounds write vulnerability in device CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setportList allows attackers to execute arbitrary code on the system via a crafted post request. Tenda AC11 The device contains an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Tenda AC11 is an AC1200 dual-band Gigabit WiFi router
VAR-202105-1614 No CVE New H3C Technology Co., Ltd. WX3520H has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
WX3520H is an enterprise-level operating wireless controller. New H3C Technology Co., Ltd. WX3520H has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202105-1615 No CVE New H3C Technology Co., Ltd. WX2540H has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
WX2540H is a wireless controller. New H3C Technology Co., Ltd. WX2540H has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202105-1670 No CVE Many H3C MSR series routers have weak password vulnerabilities CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
The MSR series router is an enterprise-level router of Xinhua Three Technology Co., Ltd. Many H3C MSR series routers have weak password vulnerabilities, which can be exploited by attackers to obtain sensitive information.
VAR-202105-1676 No CVE Multiple wireless controller products of New H3C Technology Co., Ltd. have weak password vulnerabilities CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
H3C WX3510H, H3C WX2510H, H3C WX3508H, H3C WX3540H are wireless controllers of H3C Technology Co., Ltd. Several wireless controller products of New H3C Technology Co., Ltd. have weak password vulnerabilities, which can be exploited by attackers to obtain sensitive information.
VAR-202105-1678 No CVE Prolink Technology Co., Ltd. TL-WR841HP has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
TL-WR841HP is a 300Mbps, high-power wireless router. Universal Technology Co., Ltd. TL-WR841HP has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202105-1679 No CVE Prolink Technology Co., Ltd. TL-WR940N has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
TL-WR940N is a wireless router. The TL-WR940N of Universal Technology Co., Ltd. has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202105-1680 No CVE New H3C Technology Co., Ltd. WX2560H has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
WX2560H is a gateway wireless controller independently developed by New H3C Technology Co., Ltd. New H3C Technology Co., Ltd. WX2560H has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202105-1682 No CVE H3C Beckham router has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
The H3C Xiaobei router is an enterprise-level router dedicated to shops. The H3C Beckham router has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.