VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202102-1540 No CVE The Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05411) CVSS V2: 6.8
CVSS V3: -
Severity: MEDIUM
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco). The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
VAR-202102-1541 No CVE The Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05412) CVSS V2: 6.8
CVSS V3: -
Severity: MEDIUM
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco). The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
VAR-202102-1542 No CVE Ruijie Networks RG-NBR has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
The RG-NBR series is an Internet behavior management router launched by Ruijie. It is a router designed for all office scenarios. Ruijie Networks RG-NBR has a weak password vulnerability. Attackers can use this vulnerability to log in to the background to obtain sensitive information.
VAR-202102-1543 No CVE The Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05413) CVSS V2: 6.8
CVSS V3: -
Severity: MEDIUM
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco). The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
VAR-202102-1544 No CVE Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05418) CVSS V2: 6.8
CVSS V3: -
Severity: MEDIUM
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco). The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
VAR-202102-1545 No CVE Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05419) CVSS V2: 6.8
CVSS V3: -
Severity: MEDIUM
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco). The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
VAR-202102-1546 No CVE The Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05414) CVSS V2: 6.8
CVSS V3: -
Severity: MEDIUM
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco). The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
VAR-202102-1547 No CVE The Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05415) CVSS V2: 6.8
CVSS V3: -
Severity: MEDIUM
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco). The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
VAR-202102-1548 No CVE The Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05416) CVSS V2: 6.8
CVSS V3: -
Severity: MEDIUM
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco). The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
VAR-202102-1549 No CVE Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05417) CVSS V2: 6.8
CVSS V3: -
Severity: MEDIUM
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco). The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
VAR-202102-1550 No CVE Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05422) CVSS V2: 6.8
CVSS V3: -
Severity: MEDIUM
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco). The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
VAR-202102-1551 No CVE Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05423) CVSS V2: 6.8
CVSS V3: -
Severity: MEDIUM
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco). The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
VAR-202102-1552 No CVE Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05420) CVSS V2: 6.8
CVSS V3: -
Severity: MEDIUM
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco). The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
VAR-202102-1553 No CVE The Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05421) CVSS V2: 6.8
CVSS V3: -
Severity: MEDIUM
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco). The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
VAR-202104-1262 CVE-2021-30230 An Lianbao WF-1 router has a command execution vulnerability CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
The api/ZRFirmware/set_time_zone interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the zonename parameter. Anlianbao WT-1 is a 4G router that integrates wired and wireless router access, and secure Internet access. An Lianbao WF-1 router has a command execution vulnerability, which can be exploited by attackers to gain server management rights
VAR-202104-1266 CVE-2021-30234 An Lianbao WF-1 router has a command execution vulnerability CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
The api/ZRIGMP/set_MLD_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the MLD_PROXY_WAN_CONNECT parameter. Anlianbao WT-1 is a 4G router that integrates wired and wireless router access, and secure Internet access. An Lianbao WF-1 router has a command execution vulnerability, which can be exploited by attackers to gain server management rights
VAR-202104-1265 CVE-2021-30233 An Lianbao WF-1 router has a command execution vulnerability CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
The api/ZRIptv/setIptvInfo interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the iptv_vlan parameter. Anlianbao WT-1 is a 4G router that integrates wired and wireless router access, and secure Internet access. An Lianbao WF-1 router has a command execution vulnerability, which can be exploited by attackers to gain server management rights
VAR-202104-1264 CVE-2021-30232 An Lianbao WF-1 router has a command execution vulnerability CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
The api/ZRIGMP/set_IGMP_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the IGMP_PROXY_WAN_CONNECT parameter. Anlianbao WT-1 is a 4G router that integrates wired and wireless router access, and secure Internet access. An Lianbao WF-1 router has a command execution vulnerability, which can be exploited by attackers to gain server management rights
VAR-202104-1263 CVE-2021-30231 An Lianbao WF-1 router has a command execution vulnerability CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
The api/zrDm/set_ZRElink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the bssaddr, abiaddr, devtoken, devid, elinksync, or elink_proc_enable parameter. Anlianbao WT-1 is a 4G router that integrates wired and wireless router access, and secure Internet access. An Lianbao WF-1 router has a command execution vulnerability, which can be exploited by attackers to gain server management rights
VAR-202104-1261 CVE-2021-30229 An Lianbao WF-1 router has a command execution vulnerability CVSS V2: 6.5
CVSS V3: 8.8
Severity: HIGH
The api/zrDm/set_zrDm interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the dm_enable, AppKey, or Pwd parameter. Anlianbao WT-1 is a 4G router that integrates wired and wireless router access, and secure Internet access. An Lianbao WF-1 router has a command execution vulnerability, which can be exploited by attackers to gain server management rights