VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202102-1560 No CVE Datang Telecom AC centralized management platform has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Datang Telecom Technology Co., Ltd. is a high-tech enterprise controlled by the Institute of Telecommunications Science and Technology (Datang Telecom Technology Industry Group). The company was registered and established in Beijing in 1998. In October of the same year, the "Datang Telecom" stock was listed on the Shanghai Stock Exchange. Listed. Datang Telecom’s AC centralized management platform has a weak password vulnerability. Attackers can use this vulnerability to obtain sensitive information and change device configuration.
VAR-202102-1561 No CVE Huawei Technologies Co., Ltd. Huawei TaiShan 2280 server intelligent management system IBMC has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
The Huawei TaiShan 2280 server intelligent management system IBMC (Huawei Intelligent Baseboard Management Controller, hereinafter referred to as iBMC) is an embedded server management system for the full life cycle of the server. Huawei Technologies Co., Ltd. Huawei TaiShan 2280 server intelligent management system IBMC has a weak password vulnerability. Attackers can use the vulnerability to obtain sensitive information.
VAR-202102-1570 No CVE Binary Vulnerability in Tenda W18E Enterprise Router CVSS V2: 4.3
CVSS V3: -
Severity: MEDIUM
Tenda W18E is an enterprise router. Tenda W18E enterprise router has a binary vulnerability, which can be exploited by an attacker to cause a denial of service attack.
VAR-202103-0050 CVE-2020-14516 Rockwell Automation FactoryTalk Services Platform Security hole CVSS V2: 7.5
CVSS V3: 10.0
Severity: CRITICAL
In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256 hashing algorithm with FactoryTalk Services Platform that prevents the user password from being hashed properly. It provides routine services for applications, such as diagnostic information, health monitoring and real-time data access
VAR-202103-0079 CVE-2019-18233 Advantech Spectre RT  Industrial router  ERT351  Cross-site Scripting Vulnerability CVSS V2: 4.3
CVSS V3: 6.1
Severity: MEDIUM
In Advantech Spectre RT Industrial Routers ERT351 5.1.3 and prior, the affected product does not neutralize special characters in the error response, allowing attackers to use a reflected XSS attack. Advantech Spectre RT Industrial router ERT351 Contains a cross-site scripting vulnerability.Information may be obtained and information may be tampered with. When malicious data is viewed, sensitive information can be obtained or user sessions can be hijacked
VAR-202103-0080 CVE-2019-18235 Advantech Spectre RT ERT351  Vulnerability regarding improper restriction of excessive authentication attempts in CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
Advantech Spectre RT ERT351 Versions 5.1.3 and prior has insufficient login authentication parameters required for the web application may allow an attacker to gain full access using a brute-force password attack. Advantech Spectre RT ERT351 Is vulnerable to improper restriction of excessive authentication attempts.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Advantech Spectre RT ERT351 is a router of American Advantech company that provides network routing function. Advantech Spectre RT ERT351 has security vulnerabilities that allow remote attackers to use the vulnerabilities to submit special requests and brute force to access the system
VAR-202103-0078 CVE-2019-18231 Advantech Spectre RT ERT351  Vulnerability in plaintext transmission of important information in CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
Advantech Spectre RT ERT351 Versions 5.1.3 and prior logins and passwords are transmitted in clear text form, which may allow an attacker to intercept the request. Advantech Spectre RT ERT351 Contains a vulnerability in the transmission of important information in clear text.Information may be obtained. Advantech Spectre RT ERT351 is a router of American Advantech company that provides network routing function
VAR-202102-1612 No CVE Aikuai router iK-Q80 has a denial of service vulnerability CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
The business scope of Quanxun Convergence Network Technology (Beijing) Co., Ltd. includes: operating telecommunications business; Internet information services; technology development, technology services, technology consulting, technology transfer, etc. Aikuai router iK-Q80 has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service.
VAR-202102-1614 No CVE Aikuai router has a denial of service vulnerability CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
The business scope of Quanxun Convergence Network Technology (Beijing) Co., Ltd. includes: operating telecommunications business; Internet information services; technology development, technology services, technology consulting, technology transfer, etc. The Aikuai router has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service.
VAR-202102-1616 No CVE Aikuai router has a denial of service vulnerability (CNVD-2021-03424) CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
The business scope of Quanxun Convergence Network Technology (Beijing) Co., Ltd. includes: operating telecommunications business; Internet information services; technology development, technology services, technology consulting, technology transfer, etc. The Aikuai router has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service.
VAR-202102-1625 No CVE Gargoyle OS has a denial of service vulnerability CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
Gargoyle OS is a web management interface for small router devices. Gargoyle OS has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service.
VAR-202102-1600 No CVE SQL injection vulnerability exists in WDECP-IC card metering management platform CVSS V2: 6.8
CVSS V3: -
Severity: MEDIUM
Tangshan Liulin Automation Equipment Co., Ltd. is a high-tech enterprise engaged in the research and development, production, sales and system engineering technical services of the security communication terminal and smart application platform software of the Internet of Things. The WDECP-IC card measurement management platform has a SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information in the database.
VAR-202102-1517 No CVE Command execution vulnerability exists in Cisco RV345/RV340 CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
Cisco is the world's leading provider of network solutions. Cisco RV345/RV340 has a command execution vulnerability, which can be exploited by an attacker to gain control of the server.
VAR-202102-1521 No CVE H3C NX18 Plus has a denial of service vulnerability CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
The business scope of New H3C Technology Co., Ltd. includes: technology development, technical services, technical consultation, achievement transfer, production, sales: electronic products, etc. H3C NX18 Plus has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service.
VAR-202102-1525 No CVE Totolink A3002R has a denial of service vulnerability CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
The business scope of Zeon Electronics (Shenzhen) Co., Ltd. includes R&D, production and operation of power supplies, switches, integrated circuits, routers, and computer network cards. Totolink A3002R has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service.
VAR-202102-1526 No CVE Mercury X18G router has XSS vulnerability CVSS V2: 5.5
CVSS V3: -
Severity: MEDIUM
The general business projects of Shenzhen Meikexing Communication Technology Co., Ltd. include: technical development of computer wireless LAN products, computer software and hardware, communication equipment, electronic products, and network security equipment. The Mercury X18G router has an XSS vulnerability. Attackers can use the vulnerability to obtain user cookie information.
VAR-202104-1191 CVE-2021-28075 iKuaiOS  Vulnerability in CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
iKuaiOS 3.4.8 Build 202012291059 has an arbitrary file download vulnerability, which can be exploited by attackers to obtain sensitive information. iKuaiOS Contains an unspecified vulnerability.Information may be obtained. The business scope of Quanxun Convergence Network Technology (Beijing) Co., Ltd. includes: Internet information services; technology development, technology services, technology consulting, technology transfer, technology promotion, etc
VAR-202102-0254 CVE-2020-21224 Inspur ClusterEngine  Argument insertion or modification vulnerability in CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0. A remote attacker can send a malicious login packet to the control server. Inspur ClusterEngine Is vulnerable to the insertion or modification of arguments.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Inspur Inspur ClusterEngine is an application software of China Inspur Company. Provides jobs submitted by the software and hardware in the management cluster system
VAR-202102-1597 No CVE HG220GS-U has a denial of service vulnerability CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
The business scope of Fiberhome Communication Technology Co., Ltd. includes: optical fiber communication and related communication technology, information technology, industrial Internet, and technology development in the field of Internet of Things, etc. HG220GS-U has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service.
VAR-202102-1606 No CVE MIFON Smart Router R1 has a denial of service vulnerability CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
The business scope of Fiberhome Communication Technology Co., Ltd. includes: optical fiber communication and related communication technology, information technology, industrial Internet, and technology development in the field of Internet of Things, etc. MIFON Smart Router R1 has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service.