VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202104-2055 No CVE SQL injection vulnerability exists in the water rights trading system (CNVD-2021-18287) CVSS V2: 6.8
CVSS V3: -
Severity: MEDIUM
Tangshan Liulin Automation Equipment Co., Ltd. is a high-tech enterprise specializing in the research and development, production, sales and system engineering technical services of the security communication terminal and smart application platform software of the Internet of Things. There is a SQL injection vulnerability in the water rights trading system. Attackers can use the vulnerability to obtain sensitive information in the database.
VAR-202104-2056 No CVE SQL injection vulnerability exists in the water rights trading system (CNVD-2021-18285) CVSS V2: 6.8
CVSS V3: -
Severity: MEDIUM
Tangshan Liulin Automation Equipment Co., Ltd. is a high-tech enterprise specializing in the research and development, production, sales and system engineering technical services of the security communication terminal and smart application platform software of the Internet of Things. There is a SQL injection vulnerability in the water rights trading system. Attackers can use the vulnerability to obtain sensitive information in the database.
VAR-202104-2057 No CVE SQL injection vulnerability exists in the water rights trading system (CNVD-2021-18286) CVSS V2: 6.8
CVSS V3: -
Severity: MEDIUM
Tangshan Liulin Automation Equipment Co., Ltd. is a high-tech enterprise specializing in the research and development, production, sales and system engineering technical services of the security communication terminal and smart application platform software of the Internet of Things. There is a SQL injection vulnerability in the water rights trading system. Attackers can use the vulnerability to obtain sensitive information in the database.
VAR-202104-2058 No CVE SQL injection vulnerability exists in the water rights trading system (CNVD-2021-18288) CVSS V2: 6.8
CVSS V3: -
Severity: MEDIUM
Tangshan Liulin Automation Equipment Co., Ltd. is a high-tech enterprise specializing in the research and development, production, sales and system engineering technical services of the security communication terminal and smart application platform software of the Internet of Things. There is a SQL injection vulnerability in the water rights trading system. Attackers can use the vulnerability to obtain sensitive information in the database.
VAR-202104-2059 No CVE An SQL injection vulnerability exists in the WDECP-IC card measurement management platform of Tangshan Liulin Automation Equipment Co., Ltd. CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
Tangshan Liulin Automation Equipment Co., Ltd. is a high-tech enterprise engaged in the research and development, production, sales and system engineering technical services of the security communication terminal and smart application platform software of the Internet of Things. The WDECP-IC card measurement management platform of Tangshan Liulin Automation Equipment Co., Ltd. has a SQL injection vulnerability. Attackers can use the vulnerability to obtain sensitive information in the database.
VAR-202104-2060 No CVE SQL injection vulnerability exists in the water rights trading system (CNVD-2021-18289) CVSS V2: 6.8
CVSS V3: -
Severity: MEDIUM
Tangshan Liulin Automation Equipment Co., Ltd. is a high-tech enterprise specializing in the research and development, production, sales and system engineering technical services of the security communication terminal and smart application platform software of the Internet of Things. There is a SQL injection vulnerability in the water rights trading system. Attackers can use the vulnerability to obtain sensitive information in the database.
VAR-202104-2061 No CVE SQL injection vulnerability exists in the water rights trading system (CNVD-2021-18291) CVSS V2: 6.8
CVSS V3: -
Severity: MEDIUM
Tangshan Liulin Automation Equipment Co., Ltd. is a high-tech enterprise specializing in the research and development, production, sales and system engineering technical services of the security communication terminal and smart application platform software of the Internet of Things. There is a SQL injection vulnerability in the water rights trading system. Attackers can use the vulnerability to obtain sensitive information in the database.
VAR-202104-2062 No CVE SQL injection vulnerability exists in the water rights trading system (CNVD-2021-18290) CVSS V2: 6.8
CVSS V3: -
Severity: MEDIUM
Tangshan Liulin Automation Equipment Co., Ltd. is a high-tech enterprise specializing in the research and development, production, sales and system engineering technical services of the security communication terminal and smart application platform software of the Internet of Things. There is a SQL injection vulnerability in the water rights trading system. Attackers can use the vulnerability to obtain sensitive information in the database.
VAR-202104-2063 No CVE SQL injection vulnerability exists in the water rights trading system (CNVD-2021-18297) CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
Tangshan Liulin Automation Equipment Co., Ltd. is a high-tech enterprise specializing in the research and development, production, sales and system engineering technical services of the security communication terminal and smart application platform software of the Internet of Things. There is a SQL injection vulnerability in the water rights trading system. Attackers can use the vulnerability to obtain sensitive information in the database.
VAR-202104-2064 No CVE SQL injection vulnerability exists in water rights trading system CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
Tangshan Liulin Automation Equipment Co., Ltd. is a high-tech enterprise specializing in the research and development, production, sales and system engineering technical services of the security communication terminal and smart application platform software of the Internet of Things. There is a SQL injection vulnerability in the water rights trading system. Attackers can use the vulnerability to obtain sensitive information in the database.
VAR-202104-2025 No CVE Unauthorized access vulnerability exists in ZXV10 W815N router of ZTE Corporation CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
ZTE Corporation is the world's leading provider of integrated communications solutions. The ZXV10 W815N router of ZTE Corporation has an unauthorized access vulnerability. Attackers can use the vulnerability to obtain sensitive information.
VAR-202104-2026 No CVE Four-Faith router of Xiamen Four-Faith Communication Technology Co., Ltd. has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Xiamen Sixin Communication Technology Co., Ltd. is a national high-tech enterprise, a leading enterprise of small giants of scientific and technological innovation in Fujian Province, an IoT platform enterprise, an IoT technology expert, and a provider of IoT communication equipment and solutions. The Four-Faith router of Xiamen Four-Faith Communication Technology Co., Ltd. has a weak password vulnerability. Attackers can use the vulnerability to obtain sensitive information.
VAR-202104-2027 No CVE Unauthorized access vulnerability exists in ZXHN F460 of ZTE Corporation CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
ZXHN F460 is the optical modem of ZTE's EPON mode. There is an unauthorized access vulnerability in ZXHN F460 of ZTE Corporation. Attackers can use the vulnerability to obtain sensitive information.
VAR-202104-2028 No CVE Command execution vulnerability exists in ZXHN H168N of ZTE Corporation CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
ZTE Corporation is the world's leading provider of integrated communications solutions. ZTE Corporation ZXHN H168N has a command execution vulnerability. Attackers can use this vulnerability to execute arbitrary commands.
VAR-202104-2029 No CVE ZTE Corporation ZXHN H168N has an unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
ZTE Corporation is the world's leading provider of integrated communications solutions. ZTE Corporation ZXHN H168N has an unauthorized access vulnerability. Attackers can use the vulnerability to obtain sensitive information.
VAR-202104-2030 No CVE RG-RSR series routers have weak password vulnerabilities CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Ruijie Networks Co., Ltd. is a professional network manufacturer with a full range of network equipment product lines and solutions including switches, routers, software, security firewalls, wireless products, and storage. The RG-RSR series routers have a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202104-2033 No CVE Command execution vulnerability exists in ZXHN F460 of ZTE Corporation CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
ZXHN F460 is the optical modem of ZTE's EPON mode. A command execution vulnerability exists in ZXHN F460 of ZTE Corporation. Attackers can use this vulnerability to execute arbitrary commands.
VAR-202104-1463 CVE-2021-29379 D-Link DIR-802 A1  In  OS  Command injection vulnerability CVSS V2: 5.8
CVSS V3: 8.8
Severity: HIGH
An issue was discovered on D-Link DIR-802 A1 devices through 1.00b05. Universal Plug and Play (UPnP) is enabled by default on port 1900. An attacker can perform command injection by injecting a payload into the Search Target (ST) field of the SSDP M-SEARCH discover packet. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. D-Link DIR-802 A1 Has OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. D-Link DIR-802 is a wireless router of D-Link company in Taiwan. D-Link DIR-802 A1 1.00b05 and earlier versions have a command injection vulnerability
VAR-202104-1016 CVE-2021-27486 FATEK Automation  Made  WinProladder  Integer underflow vulnerabilities CVSS V2: 6.8
CVSS V3: 7.8
Severity: HIGH
FATEK Automation WinProladder Versions 3.30 and prior is vulnerable to an integer underflow, which may cause an out-of-bounds write and allow an attacker to execute arbitrary code. FATEK Automation Provided by the company WinProladder Is Windows Ladder programming software for. The official version of WinProLadder is a very good practical PLC programming tool
VAR-202104-1666 CVE-2021-3128 ASUS RT-AX3000 Security hole CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device and its upstream ISP's router. This occurs when a link prefix route points to a point-to-point link, a destination IPv6 address belongs to the prefix and is not a local IPv6 address, and a router advertisement is received with at least one global unique IPv6 prefix for which the on-link flag is set