VARIoT IoT vulnerabilities database
| VAR-202102-1540 | No CVE | The Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05411) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco).
The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
| VAR-202102-1541 | No CVE | The Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05412) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco).
The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
| VAR-202102-1542 | No CVE | Ruijie Networks RG-NBR has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
The RG-NBR series is an Internet behavior management router launched by Ruijie. It is a router designed for all office scenarios.
Ruijie Networks RG-NBR has a weak password vulnerability. Attackers can use this vulnerability to log in to the background to obtain sensitive information.
| VAR-202102-1543 | No CVE | The Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05413) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco).
The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
| VAR-202102-1544 | No CVE | Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05418) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco).
The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
| VAR-202102-1545 | No CVE | Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05419) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco).
The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
| VAR-202102-1546 | No CVE | The Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05414) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco).
The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
| VAR-202102-1547 | No CVE | The Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05415) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco).
The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
| VAR-202102-1548 | No CVE | The Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05416) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco).
The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
| VAR-202102-1549 | No CVE | Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05417) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco).
The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
| VAR-202102-1550 | No CVE | Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05422) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco).
The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
| VAR-202102-1551 | No CVE | Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05423) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco).
The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
| VAR-202102-1552 | No CVE | Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05420) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco).
The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
| VAR-202102-1553 | No CVE | The Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05421) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco).
The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
| VAR-202104-1262 | CVE-2021-30230 | An Lianbao WF-1 router has a command execution vulnerability |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
The api/ZRFirmware/set_time_zone interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the zonename parameter. Anlianbao WT-1 is a 4G router that integrates wired and wireless router access, and secure Internet access.
An Lianbao WF-1 router has a command execution vulnerability, which can be exploited by attackers to gain server management rights
| VAR-202104-1266 | CVE-2021-30234 | An Lianbao WF-1 router has a command execution vulnerability |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
The api/ZRIGMP/set_MLD_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the MLD_PROXY_WAN_CONNECT parameter. Anlianbao WT-1 is a 4G router that integrates wired and wireless router access, and secure Internet access.
An Lianbao WF-1 router has a command execution vulnerability, which can be exploited by attackers to gain server management rights
| VAR-202104-1265 | CVE-2021-30233 | An Lianbao WF-1 router has a command execution vulnerability |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
The api/ZRIptv/setIptvInfo interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the iptv_vlan parameter. Anlianbao WT-1 is a 4G router that integrates wired and wireless router access, and secure Internet access.
An Lianbao WF-1 router has a command execution vulnerability, which can be exploited by attackers to gain server management rights
| VAR-202104-1264 | CVE-2021-30232 | An Lianbao WF-1 router has a command execution vulnerability |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
The api/ZRIGMP/set_IGMP_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the IGMP_PROXY_WAN_CONNECT parameter. Anlianbao WT-1 is a 4G router that integrates wired and wireless router access, and secure Internet access.
An Lianbao WF-1 router has a command execution vulnerability, which can be exploited by attackers to gain server management rights
| VAR-202104-1263 | CVE-2021-30231 | An Lianbao WF-1 router has a command execution vulnerability |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
The api/zrDm/set_ZRElink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the bssaddr, abiaddr, devtoken, devid, elinksync, or elink_proc_enable parameter. Anlianbao WT-1 is a 4G router that integrates wired and wireless router access, and secure Internet access.
An Lianbao WF-1 router has a command execution vulnerability, which can be exploited by attackers to gain server management rights
| VAR-202104-1261 | CVE-2021-30229 | An Lianbao WF-1 router has a command execution vulnerability |
CVSS V2: 6.5 CVSS V3: 8.8 Severity: HIGH |
The api/zrDm/set_zrDm interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the dm_enable, AppKey, or Pwd parameter. Anlianbao WT-1 is a 4G router that integrates wired and wireless router access, and secure Internet access.
An Lianbao WF-1 router has a command execution vulnerability, which can be exploited by attackers to gain server management rights