VARIoT IoT vulnerabilities database
| VAR-202104-2055 | No CVE | SQL injection vulnerability exists in the water rights trading system (CNVD-2021-18287) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Tangshan Liulin Automation Equipment Co., Ltd. is a high-tech enterprise specializing in the research and development, production, sales and system engineering technical services of the security communication terminal and smart application platform software of the Internet of Things.
There is a SQL injection vulnerability in the water rights trading system. Attackers can use the vulnerability to obtain sensitive information in the database.
| VAR-202104-2056 | No CVE | SQL injection vulnerability exists in the water rights trading system (CNVD-2021-18285) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Tangshan Liulin Automation Equipment Co., Ltd. is a high-tech enterprise specializing in the research and development, production, sales and system engineering technical services of the security communication terminal and smart application platform software of the Internet of Things.
There is a SQL injection vulnerability in the water rights trading system. Attackers can use the vulnerability to obtain sensitive information in the database.
| VAR-202104-2057 | No CVE | SQL injection vulnerability exists in the water rights trading system (CNVD-2021-18286) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Tangshan Liulin Automation Equipment Co., Ltd. is a high-tech enterprise specializing in the research and development, production, sales and system engineering technical services of the security communication terminal and smart application platform software of the Internet of Things.
There is a SQL injection vulnerability in the water rights trading system. Attackers can use the vulnerability to obtain sensitive information in the database.
| VAR-202104-2058 | No CVE | SQL injection vulnerability exists in the water rights trading system (CNVD-2021-18288) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Tangshan Liulin Automation Equipment Co., Ltd. is a high-tech enterprise specializing in the research and development, production, sales and system engineering technical services of the security communication terminal and smart application platform software of the Internet of Things.
There is a SQL injection vulnerability in the water rights trading system. Attackers can use the vulnerability to obtain sensitive information in the database.
| VAR-202104-2059 | No CVE | An SQL injection vulnerability exists in the WDECP-IC card measurement management platform of Tangshan Liulin Automation Equipment Co., Ltd. |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
Tangshan Liulin Automation Equipment Co., Ltd. is a high-tech enterprise engaged in the research and development, production, sales and system engineering technical services of the security communication terminal and smart application platform software of the Internet of Things.
The WDECP-IC card measurement management platform of Tangshan Liulin Automation Equipment Co., Ltd. has a SQL injection vulnerability. Attackers can use the vulnerability to obtain sensitive information in the database.
| VAR-202104-2060 | No CVE | SQL injection vulnerability exists in the water rights trading system (CNVD-2021-18289) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Tangshan Liulin Automation Equipment Co., Ltd. is a high-tech enterprise specializing in the research and development, production, sales and system engineering technical services of the security communication terminal and smart application platform software of the Internet of Things.
There is a SQL injection vulnerability in the water rights trading system. Attackers can use the vulnerability to obtain sensitive information in the database.
| VAR-202104-2061 | No CVE | SQL injection vulnerability exists in the water rights trading system (CNVD-2021-18291) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Tangshan Liulin Automation Equipment Co., Ltd. is a high-tech enterprise specializing in the research and development, production, sales and system engineering technical services of the security communication terminal and smart application platform software of the Internet of Things.
There is a SQL injection vulnerability in the water rights trading system. Attackers can use the vulnerability to obtain sensitive information in the database.
| VAR-202104-2062 | No CVE | SQL injection vulnerability exists in the water rights trading system (CNVD-2021-18290) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Tangshan Liulin Automation Equipment Co., Ltd. is a high-tech enterprise specializing in the research and development, production, sales and system engineering technical services of the security communication terminal and smart application platform software of the Internet of Things.
There is a SQL injection vulnerability in the water rights trading system. Attackers can use the vulnerability to obtain sensitive information in the database.
| VAR-202104-2063 | No CVE | SQL injection vulnerability exists in the water rights trading system (CNVD-2021-18297) |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
Tangshan Liulin Automation Equipment Co., Ltd. is a high-tech enterprise specializing in the research and development, production, sales and system engineering technical services of the security communication terminal and smart application platform software of the Internet of Things.
There is a SQL injection vulnerability in the water rights trading system. Attackers can use the vulnerability to obtain sensitive information in the database.
| VAR-202104-2064 | No CVE | SQL injection vulnerability exists in water rights trading system |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
Tangshan Liulin Automation Equipment Co., Ltd. is a high-tech enterprise specializing in the research and development, production, sales and system engineering technical services of the security communication terminal and smart application platform software of the Internet of Things.
There is a SQL injection vulnerability in the water rights trading system. Attackers can use the vulnerability to obtain sensitive information in the database.
| VAR-202104-2025 | No CVE | Unauthorized access vulnerability exists in ZXV10 W815N router of ZTE Corporation |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
ZTE Corporation is the world's leading provider of integrated communications solutions.
The ZXV10 W815N router of ZTE Corporation has an unauthorized access vulnerability. Attackers can use the vulnerability to obtain sensitive information.
| VAR-202104-2026 | No CVE | Four-Faith router of Xiamen Four-Faith Communication Technology Co., Ltd. has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Xiamen Sixin Communication Technology Co., Ltd. is a national high-tech enterprise, a leading enterprise of small giants of scientific and technological innovation in Fujian Province, an IoT platform enterprise, an IoT technology expert, and a provider of IoT communication equipment and solutions.
The Four-Faith router of Xiamen Four-Faith Communication Technology Co., Ltd. has a weak password vulnerability. Attackers can use the vulnerability to obtain sensitive information.
| VAR-202104-2027 | No CVE | Unauthorized access vulnerability exists in ZXHN F460 of ZTE Corporation |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
ZXHN F460 is the optical modem of ZTE's EPON mode.
There is an unauthorized access vulnerability in ZXHN F460 of ZTE Corporation. Attackers can use the vulnerability to obtain sensitive information.
| VAR-202104-2028 | No CVE | Command execution vulnerability exists in ZXHN H168N of ZTE Corporation |
CVSS V2: 10.0 CVSS V3: - Severity: HIGH |
ZTE Corporation is the world's leading provider of integrated communications solutions.
ZTE Corporation ZXHN H168N has a command execution vulnerability. Attackers can use this vulnerability to execute arbitrary commands.
| VAR-202104-2029 | No CVE | ZTE Corporation ZXHN H168N has an unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
ZTE Corporation is the world's leading provider of integrated communications solutions.
ZTE Corporation ZXHN H168N has an unauthorized access vulnerability. Attackers can use the vulnerability to obtain sensitive information.
| VAR-202104-2030 | No CVE | RG-RSR series routers have weak password vulnerabilities |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Ruijie Networks Co., Ltd. is a professional network manufacturer with a full range of network equipment product lines and solutions including switches, routers, software, security firewalls, wireless products, and storage.
The RG-RSR series routers have a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202104-2033 | No CVE | Command execution vulnerability exists in ZXHN F460 of ZTE Corporation |
CVSS V2: 10.0 CVSS V3: - Severity: HIGH |
ZXHN F460 is the optical modem of ZTE's EPON mode.
A command execution vulnerability exists in ZXHN F460 of ZTE Corporation. Attackers can use this vulnerability to execute arbitrary commands.
| VAR-202104-1463 | CVE-2021-29379 | D-Link DIR-802 A1 In OS Command injection vulnerability |
CVSS V2: 5.8 CVSS V3: 8.8 Severity: HIGH |
An issue was discovered on D-Link DIR-802 A1 devices through 1.00b05. Universal Plug and Play (UPnP) is enabled by default on port 1900. An attacker can perform command injection by injecting a payload into the Search Target (ST) field of the SSDP M-SEARCH discover packet. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. D-Link DIR-802 A1 Has OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. D-Link DIR-802 is a wireless router of D-Link company in Taiwan.
D-Link DIR-802 A1 1.00b05 and earlier versions have a command injection vulnerability
| VAR-202104-1016 | CVE-2021-27486 | FATEK Automation Made WinProladder Integer underflow vulnerabilities |
CVSS V2: 6.8 CVSS V3: 7.8 Severity: HIGH |
FATEK Automation WinProladder Versions 3.30 and prior is vulnerable to an integer underflow, which may cause an out-of-bounds write and allow an attacker to execute arbitrary code. FATEK Automation Provided by the company WinProladder Is Windows Ladder programming software for. The official version of WinProLadder is a very good practical PLC programming tool
| VAR-202104-1666 | CVE-2021-3128 | ASUS RT-AX3000 Security hole |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device and its upstream ISP's router. This occurs when a link prefix route points to a point-to-point link, a destination IPv6 address belongs to the prefix and is not a local IPv6 address, and a router advertisement is received with at least one global unique IPv6 prefix for which the on-link flag is set