VARIoT IoT vulnerabilities database
| VAR-202103-1694 | No CVE | Inhantong InRouter900 industrial router has command execution vulnerability (CNVD-2021-10445) |
CVSS V2: 9.0 CVSS V3: - Severity: HIGH |
Inhantong InRouter900 series industrial routers are 4G industrial routers.
Inhantong InRouter900 industrial router has a command execution vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to execute arbitrary commands on the system.
| VAR-202103-1695 | No CVE | Inhantong InRouter900 industrial router has command execution vulnerability (CNVD-2021-10447) |
CVSS V2: 9.0 CVSS V3: - Severity: HIGH |
Inhantong InRouter900 series industrial routers are 4G industrial routers.
Inhantong InRouter900 industrial router has a command execution vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to execute arbitrary commands on the system.
| VAR-202103-1696 | No CVE | Inhantong InRouter900 industrial router has arbitrary file reading vulnerabilities |
CVSS V2: 4.0 CVSS V3: - Severity: MEDIUM |
Inhantong InRouter900 series industrial routers are 4G industrial routers.
Inhantong InRouter900 industrial router has an arbitrary file reading vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to read arbitrary files.
| VAR-202103-1697 | No CVE | Inhantong InRouter900 industrial router has arbitrary file deletion vulnerability |
CVSS V2: 4.0 CVSS V3: - Severity: MEDIUM |
Inhantong InRouter900 series industrial routers are 4G industrial routers.
Inhantong InRouter900 industrial router has an arbitrary file deletion vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to delete arbitrary files.
| VAR-202103-1698 | No CVE | Fibrsol Global Network FS801GW has an information disclosure vulnerability |
CVSS V2: 6.4 CVSS V3: - Severity: MEDIUM |
Fibsol Global Network Co., Ltd. specializes in the design, development and manufacturing of optical fiber network products and components.
Fibrsol Global Network FS801GW has an information disclosure vulnerability. Attackers can use this vulnerability to successfully log in to the background through the background password to obtain sensitive information.
| VAR-202103-1699 | No CVE | TP-LINK TL-WR740N has weak password vulnerability |
CVSS V2: 6.4 CVSS V3: - Severity: MEDIUM |
TL-WR740N is a wireless router in the 150Mbps product line of TP-LINK.
TP-LINK TL-WR740N has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202103-1700 | No CVE | Inhantong InRouter900 industrial router has a command execution vulnerability (CNVD-2021-10451) |
CVSS V2: 9.0 CVSS V3: - Severity: HIGH |
Inhantong InRouter900 series industrial routers are 4G industrial routers.
Inhantong InRouter900 industrial router has a command execution vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to execute arbitrary commands on the system.
| VAR-202103-1701 | No CVE | Inhantong InRouter900 industrial router has a command execution vulnerability (CNVD-2021-10453) |
CVSS V2: 9.0 CVSS V3: - Severity: HIGH |
Inhantong InRouter900 series industrial routers are 4G industrial routers.
Inhantong InRouter900 industrial router has a command execution vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to execute arbitrary commands on the system.
| VAR-202103-1702 | No CVE | Inhantong InRouter900 industrial router has a command execution vulnerability (CNVD-2021-10454) |
CVSS V2: 9.0 CVSS V3: - Severity: HIGH |
Inhantong InRouter900 series industrial routers are 4G industrial routers.
Inhantong InRouter900 industrial router has a command execution vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to execute arbitrary commands on the system.
| VAR-202103-1703 | No CVE | Inhantong InRouter900 industrial router has command execution vulnerability (CNVD-2021-10452) |
CVSS V2: 9.0 CVSS V3: - Severity: HIGH |
Inhantong InRouter900 series industrial routers are 4G industrial routers.
Inhantong InRouter900 industrial router has a command execution vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to execute arbitrary commands on the system.
| VAR-202103-1704 | No CVE | Inhantong InRouter900 industrial router has command execution vulnerability (CNVD-2021-10450) |
CVSS V2: 9.0 CVSS V3: - Severity: HIGH |
Inhantong InRouter900 series industrial routers are 4G industrial routers.
Inhantong InRouter900 industrial router has a command execution vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to execute arbitrary commands on the system.
| VAR-202103-1705 | No CVE | Inhantong InRouter900 industrial router has command execution vulnerabilities |
CVSS V2: 9.0 CVSS V3: - Severity: HIGH |
Inhantong InRouter900 series industrial routers are 4G industrial routers.
Inhantong InRouter900 industrial router has a command execution vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to execute arbitrary commands on the system.
| VAR-202103-1706 | No CVE | Syrotech SY-GPON-1110-WDAONT and SY-GPON-1110-WDCONT have weak password vulnerabilities in the backend |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
SY-GPON-1110-WDAONT and SY-GPON-1110-WDCONT are routers of Syrotech Company.
Syrotech SY-GPON-1110-WDAONT and SY-GPON-1110-WDCONT have a weak password vulnerability in the backend. Attackers can use this vulnerability to successfully log in to the backend management system to obtain sensitive information.
| VAR-202103-1707 | No CVE | Various Binatone products have information disclosure vulnerabilities |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Binatone is a leading company dedicated to providing innovative consumer electronics and lifestyle products.
Many Binatone products have information disclosure vulnerabilities. Attackers can use this vulnerability to successfully log in to the background to obtain sensitive information.
| VAR-202103-1793 | No CVE | Allen-Bradley CompactLogix L16ER has industrial control equipment vulnerabilities |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
Allen-Bradley Automation provides customers with a complete set of components, products, control and information platforms, as well as support services and manufacturing solutions.
Allen-Bradley CompactLogix L16ER has industrial control equipment vulnerabilities. Attackers can use vulnerabilities to cause an internal error in the controller to be prompted when the engineering software is connected, and it cannot be recovered automatically.
| VAR-202103-1795 | No CVE | ZTE ZXHN F652 has a denial of service vulnerability |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
ZXHN F652 is a light cat from ZTE.
ZTE ZXHN F652 has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service attack.
| VAR-202103-1799 | No CVE | The Star Mini has a memory corruption vulnerability |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
Tianxing Mini is a configuration software product launched by Beijing Tianxing Configuration Software Co., Ltd.
The Star Mini has a memory corruption vulnerability. Attackers can use vulnerabilities to analyze malformed pictures that can cause program crashes.
| VAR-202103-1708 | No CVE | TP-Link TL-WVR1300G has a denial of service vulnerability |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
TL-WVR1300G is an enterprise-class wireless VPN router from TP-Link.
TP-Link TL-WVR1300G has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service attack.
| VAR-202103-1709 | No CVE | TP-Link TL-WVR1300L has a denial of service vulnerability |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
TL-WVR1300L is an enterprise-class wireless VPN router from TP-Link.
TP-Link TL-WVR1300L has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service attack.
| VAR-202103-1710 | No CVE | TP-Link TL-WVR1200L has a denial of service vulnerability |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
TL-WVR1200L is an enterprise-class wireless VPN router from TP-Link.
TP-Link TL-WVR1200L has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service attack.