VARIoT IoT vulnerabilities database
| VAR-202102-1560 | No CVE | Datang Telecom AC centralized management platform has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Datang Telecom Technology Co., Ltd. is a high-tech enterprise controlled by the Institute of Telecommunications Science and Technology (Datang Telecom Technology Industry Group). The company was registered and established in Beijing in 1998. In October of the same year, the "Datang Telecom" stock was listed on the Shanghai Stock Exchange. Listed.
Datang Telecom’s AC centralized management platform has a weak password vulnerability. Attackers can use this vulnerability to obtain sensitive information and change device configuration.
| VAR-202102-1561 | No CVE | Huawei Technologies Co., Ltd. Huawei TaiShan 2280 server intelligent management system IBMC has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
The Huawei TaiShan 2280 server intelligent management system IBMC (Huawei Intelligent Baseboard Management Controller, hereinafter referred to as iBMC) is an embedded server management system for the full life cycle of the server.
Huawei Technologies Co., Ltd. Huawei TaiShan 2280 server intelligent management system IBMC has a weak password vulnerability. Attackers can use the vulnerability to obtain sensitive information.
| VAR-202102-1570 | No CVE | Binary Vulnerability in Tenda W18E Enterprise Router |
CVSS V2: 4.3 CVSS V3: - Severity: MEDIUM |
Tenda W18E is an enterprise router.
Tenda W18E enterprise router has a binary vulnerability, which can be exploited by an attacker to cause a denial of service attack.
| VAR-202103-0050 | CVE-2020-14516 | Rockwell Automation FactoryTalk Services Platform Security hole |
CVSS V2: 7.5 CVSS V3: 10.0 Severity: CRITICAL |
In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256 hashing algorithm with FactoryTalk Services Platform that prevents the user password from being hashed properly. It provides routine services for applications, such as diagnostic information, health monitoring and real-time data access
| VAR-202103-0079 | CVE-2019-18233 | Advantech Spectre RT Industrial router ERT351 Cross-site Scripting Vulnerability |
CVSS V2: 4.3 CVSS V3: 6.1 Severity: MEDIUM |
In Advantech Spectre RT Industrial Routers ERT351 5.1.3 and prior, the affected product does not neutralize special characters in the error response, allowing attackers to use a reflected XSS attack. Advantech Spectre RT Industrial router ERT351 Contains a cross-site scripting vulnerability.Information may be obtained and information may be tampered with. When malicious data is viewed, sensitive information can be obtained or user sessions can be hijacked
| VAR-202103-0080 | CVE-2019-18235 | Advantech Spectre RT ERT351 Vulnerability regarding improper restriction of excessive authentication attempts in |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
Advantech Spectre RT ERT351 Versions 5.1.3 and prior has insufficient login authentication parameters required for the web application may allow an attacker to gain full access using a brute-force password attack. Advantech Spectre RT ERT351 Is vulnerable to improper restriction of excessive authentication attempts.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Advantech Spectre RT ERT351 is a router of American Advantech company that provides network routing function.
Advantech Spectre RT ERT351 has security vulnerabilities that allow remote attackers to use the vulnerabilities to submit special requests and brute force to access the system
| VAR-202103-0078 | CVE-2019-18231 | Advantech Spectre RT ERT351 Vulnerability in plaintext transmission of important information in |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
Advantech Spectre RT ERT351 Versions 5.1.3 and prior logins and passwords are transmitted in clear text form, which may allow an attacker to intercept the request. Advantech Spectre RT ERT351 Contains a vulnerability in the transmission of important information in clear text.Information may be obtained. Advantech Spectre RT ERT351 is a router of American Advantech company that provides network routing function
| VAR-202102-1612 | No CVE | Aikuai router iK-Q80 has a denial of service vulnerability |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
The business scope of Quanxun Convergence Network Technology (Beijing) Co., Ltd. includes: operating telecommunications business; Internet information services; technology development, technology services, technology consulting, technology transfer, etc.
Aikuai router iK-Q80 has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service.
| VAR-202102-1614 | No CVE | Aikuai router has a denial of service vulnerability |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
The business scope of Quanxun Convergence Network Technology (Beijing) Co., Ltd. includes: operating telecommunications business; Internet information services; technology development, technology services, technology consulting, technology transfer, etc.
The Aikuai router has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service.
| VAR-202102-1616 | No CVE | Aikuai router has a denial of service vulnerability (CNVD-2021-03424) |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
The business scope of Quanxun Convergence Network Technology (Beijing) Co., Ltd. includes: operating telecommunications business; Internet information services; technology development, technology services, technology consulting, technology transfer, etc.
The Aikuai router has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service.
| VAR-202102-1625 | No CVE | Gargoyle OS has a denial of service vulnerability |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
Gargoyle OS is a web management interface for small router devices.
Gargoyle OS has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service.
| VAR-202102-1600 | No CVE | SQL injection vulnerability exists in WDECP-IC card metering management platform |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Tangshan Liulin Automation Equipment Co., Ltd. is a high-tech enterprise engaged in the research and development, production, sales and system engineering technical services of the security communication terminal and smart application platform software of the Internet of Things.
The WDECP-IC card measurement management platform has a SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information in the database.
| VAR-202102-1517 | No CVE | Command execution vulnerability exists in Cisco RV345/RV340 |
CVSS V2: 10.0 CVSS V3: - Severity: HIGH |
Cisco is the world's leading provider of network solutions.
Cisco RV345/RV340 has a command execution vulnerability, which can be exploited by an attacker to gain control of the server.
| VAR-202102-1521 | No CVE | H3C NX18 Plus has a denial of service vulnerability |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
The business scope of New H3C Technology Co., Ltd. includes: technology development, technical services, technical consultation, achievement transfer, production, sales: electronic products, etc.
H3C NX18 Plus has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service.
| VAR-202102-1525 | No CVE | Totolink A3002R has a denial of service vulnerability |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
The business scope of Zeon Electronics (Shenzhen) Co., Ltd. includes R&D, production and operation of power supplies, switches, integrated circuits, routers, and computer network cards.
Totolink A3002R has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service.
| VAR-202102-1526 | No CVE | Mercury X18G router has XSS vulnerability |
CVSS V2: 5.5 CVSS V3: - Severity: MEDIUM |
The general business projects of Shenzhen Meikexing Communication Technology Co., Ltd. include: technical development of computer wireless LAN products, computer software and hardware, communication equipment, electronic products, and network security equipment.
The Mercury X18G router has an XSS vulnerability. Attackers can use the vulnerability to obtain user cookie information.
| VAR-202104-1191 | CVE-2021-28075 | iKuaiOS Vulnerability in |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
iKuaiOS 3.4.8 Build 202012291059 has an arbitrary file download vulnerability, which can be exploited by attackers to obtain sensitive information. iKuaiOS Contains an unspecified vulnerability.Information may be obtained. The business scope of Quanxun Convergence Network Technology (Beijing) Co., Ltd. includes: Internet information services; technology development, technology services, technology consulting, technology transfer, technology promotion, etc
| VAR-202102-0254 | CVE-2020-21224 | Inspur ClusterEngine Argument insertion or modification vulnerability in |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0. A remote attacker can send a malicious login packet to the control server. Inspur ClusterEngine Is vulnerable to the insertion or modification of arguments.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Inspur Inspur ClusterEngine is an application software of China Inspur Company. Provides jobs submitted by the software and hardware in the management cluster system
| VAR-202102-1597 | No CVE | HG220GS-U has a denial of service vulnerability |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
The business scope of Fiberhome Communication Technology Co., Ltd. includes: optical fiber communication and related communication technology, information technology, industrial Internet, and technology development in the field of Internet of Things, etc.
HG220GS-U has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service.
| VAR-202102-1606 | No CVE | MIFON Smart Router R1 has a denial of service vulnerability |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
The business scope of Fiberhome Communication Technology Co., Ltd. includes: optical fiber communication and related communication technology, information technology, industrial Internet, and technology development in the field of Internet of Things, etc.
MIFON Smart Router R1 has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service.