VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202103-1694 No CVE Inhantong InRouter900 industrial router has command execution vulnerability (CNVD-2021-10445) CVSS V2: 9.0
CVSS V3: -
Severity: HIGH
Inhantong InRouter900 series industrial routers are 4G industrial routers. Inhantong InRouter900 industrial router has a command execution vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to execute arbitrary commands on the system.
VAR-202103-1695 No CVE Inhantong InRouter900 industrial router has command execution vulnerability (CNVD-2021-10447) CVSS V2: 9.0
CVSS V3: -
Severity: HIGH
Inhantong InRouter900 series industrial routers are 4G industrial routers. Inhantong InRouter900 industrial router has a command execution vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to execute arbitrary commands on the system.
VAR-202103-1696 No CVE Inhantong InRouter900 industrial router has arbitrary file reading vulnerabilities CVSS V2: 4.0
CVSS V3: -
Severity: MEDIUM
Inhantong InRouter900 series industrial routers are 4G industrial routers. Inhantong InRouter900 industrial router has an arbitrary file reading vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to read arbitrary files.
VAR-202103-1697 No CVE Inhantong InRouter900 industrial router has arbitrary file deletion vulnerability CVSS V2: 4.0
CVSS V3: -
Severity: MEDIUM
Inhantong InRouter900 series industrial routers are 4G industrial routers. Inhantong InRouter900 industrial router has an arbitrary file deletion vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to delete arbitrary files.
VAR-202103-1698 No CVE Fibrsol Global Network FS801GW has an information disclosure vulnerability CVSS V2: 6.4
CVSS V3: -
Severity: MEDIUM
Fibsol Global Network Co., Ltd. specializes in the design, development and manufacturing of optical fiber network products and components. Fibrsol Global Network FS801GW has an information disclosure vulnerability. Attackers can use this vulnerability to successfully log in to the background through the background password to obtain sensitive information.
VAR-202103-1699 No CVE TP-LINK TL-WR740N has weak password vulnerability CVSS V2: 6.4
CVSS V3: -
Severity: MEDIUM
TL-WR740N is a wireless router in the 150Mbps product line of TP-LINK. TP-LINK TL-WR740N has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202103-1700 No CVE Inhantong InRouter900 industrial router has a command execution vulnerability (CNVD-2021-10451) CVSS V2: 9.0
CVSS V3: -
Severity: HIGH
Inhantong InRouter900 series industrial routers are 4G industrial routers. Inhantong InRouter900 industrial router has a command execution vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to execute arbitrary commands on the system.
VAR-202103-1701 No CVE Inhantong InRouter900 industrial router has a command execution vulnerability (CNVD-2021-10453) CVSS V2: 9.0
CVSS V3: -
Severity: HIGH
Inhantong InRouter900 series industrial routers are 4G industrial routers. Inhantong InRouter900 industrial router has a command execution vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to execute arbitrary commands on the system.
VAR-202103-1702 No CVE Inhantong InRouter900 industrial router has a command execution vulnerability (CNVD-2021-10454) CVSS V2: 9.0
CVSS V3: -
Severity: HIGH
Inhantong InRouter900 series industrial routers are 4G industrial routers. Inhantong InRouter900 industrial router has a command execution vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to execute arbitrary commands on the system.
VAR-202103-1703 No CVE Inhantong InRouter900 industrial router has command execution vulnerability (CNVD-2021-10452) CVSS V2: 9.0
CVSS V3: -
Severity: HIGH
Inhantong InRouter900 series industrial routers are 4G industrial routers. Inhantong InRouter900 industrial router has a command execution vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to execute arbitrary commands on the system.
VAR-202103-1704 No CVE Inhantong InRouter900 industrial router has command execution vulnerability (CNVD-2021-10450) CVSS V2: 9.0
CVSS V3: -
Severity: HIGH
Inhantong InRouter900 series industrial routers are 4G industrial routers. Inhantong InRouter900 industrial router has a command execution vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to execute arbitrary commands on the system.
VAR-202103-1705 No CVE Inhantong InRouter900 industrial router has command execution vulnerabilities CVSS V2: 9.0
CVSS V3: -
Severity: HIGH
Inhantong InRouter900 series industrial routers are 4G industrial routers. Inhantong InRouter900 industrial router has a command execution vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to execute arbitrary commands on the system.
VAR-202103-1706 No CVE Syrotech SY-GPON-1110-WDAONT and SY-GPON-1110-WDCONT have weak password vulnerabilities in the backend CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
SY-GPON-1110-WDAONT and SY-GPON-1110-WDCONT are routers of Syrotech Company. Syrotech SY-GPON-1110-WDAONT and SY-GPON-1110-WDCONT have a weak password vulnerability in the backend. Attackers can use this vulnerability to successfully log in to the backend management system to obtain sensitive information.
VAR-202103-1707 No CVE Various Binatone products have information disclosure vulnerabilities CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Binatone is a leading company dedicated to providing innovative consumer electronics and lifestyle products. Many Binatone products have information disclosure vulnerabilities. Attackers can use this vulnerability to successfully log in to the background to obtain sensitive information.
VAR-202103-1793 No CVE Allen-Bradley CompactLogix L16ER has industrial control equipment vulnerabilities CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
Allen-Bradley Automation provides customers with a complete set of components, products, control and information platforms, as well as support services and manufacturing solutions. Allen-Bradley CompactLogix L16ER has industrial control equipment vulnerabilities. Attackers can use vulnerabilities to cause an internal error in the controller to be prompted when the engineering software is connected, and it cannot be recovered automatically.
VAR-202103-1795 No CVE ZTE ZXHN F652 has a denial of service vulnerability CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
ZXHN F652 is a light cat from ZTE. ZTE ZXHN F652 has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service attack.
VAR-202103-1799 No CVE The Star Mini has a memory corruption vulnerability CVSS V2: 4.9
CVSS V3: -
Severity: MEDIUM
Tianxing Mini is a configuration software product launched by Beijing Tianxing Configuration Software Co., Ltd. The Star Mini has a memory corruption vulnerability. Attackers can use vulnerabilities to analyze malformed pictures that can cause program crashes.
VAR-202103-1708 No CVE TP-Link TL-WVR1300G has a denial of service vulnerability CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
TL-WVR1300G is an enterprise-class wireless VPN router from TP-Link. TP-Link TL-WVR1300G has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service attack.
VAR-202103-1709 No CVE TP-Link TL-WVR1300L has a denial of service vulnerability CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
TL-WVR1300L is an enterprise-class wireless VPN router from TP-Link. TP-Link TL-WVR1300L has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service attack.
VAR-202103-1710 No CVE TP-Link TL-WVR1200L has a denial of service vulnerability CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
TL-WVR1200L is an enterprise-class wireless VPN router from TP-Link. TP-Link TL-WVR1200L has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service attack.