VARIoT IoT vulnerabilities database
| VAR-202102-1543 | No CVE | The Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05413) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco).
The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
| VAR-202102-1544 | No CVE | Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05418) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco).
The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
| VAR-202102-1545 | No CVE | Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05419) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco).
The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
| VAR-202102-1546 | No CVE | The Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05414) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco).
The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
| VAR-202102-1547 | No CVE | The Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05415) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco).
The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
| VAR-202102-1548 | No CVE | The Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05416) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco).
The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
| VAR-202102-1549 | No CVE | Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05417) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco).
The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
| VAR-202102-1550 | No CVE | Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05422) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco).
The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
| VAR-202102-1551 | No CVE | Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05423) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco).
The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
| VAR-202102-1552 | No CVE | Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05420) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco).
The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
| VAR-202102-1553 | No CVE | The Cisco RV110W product has a buffer overflow vulnerability (CNVD-2021-05421) |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Cisco RV110W Wireless-N VPN Firewall is an enterprise-level router of Cisco (Cisco).
The Cisco RV110W product has a buffer overflow vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to exploit the vulnerability to execute arbitrary code on the system.
| VAR-202104-1262 | CVE-2021-30230 | An Lianbao WF-1 router has a command execution vulnerability |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
The api/ZRFirmware/set_time_zone interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the zonename parameter. Anlianbao WT-1 is a 4G router that integrates wired and wireless router access, and secure Internet access.
An Lianbao WF-1 router has a command execution vulnerability, which can be exploited by attackers to gain server management rights
| VAR-202104-1266 | CVE-2021-30234 | An Lianbao WF-1 router has a command execution vulnerability |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
The api/ZRIGMP/set_MLD_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the MLD_PROXY_WAN_CONNECT parameter. Anlianbao WT-1 is a 4G router that integrates wired and wireless router access, and secure Internet access.
An Lianbao WF-1 router has a command execution vulnerability, which can be exploited by attackers to gain server management rights
| VAR-202104-1265 | CVE-2021-30233 | An Lianbao WF-1 router has a command execution vulnerability |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
The api/ZRIptv/setIptvInfo interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the iptv_vlan parameter. Anlianbao WT-1 is a 4G router that integrates wired and wireless router access, and secure Internet access.
An Lianbao WF-1 router has a command execution vulnerability, which can be exploited by attackers to gain server management rights
| VAR-202104-1264 | CVE-2021-30232 | An Lianbao WF-1 router has a command execution vulnerability |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
The api/ZRIGMP/set_IGMP_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the IGMP_PROXY_WAN_CONNECT parameter. Anlianbao WT-1 is a 4G router that integrates wired and wireless router access, and secure Internet access.
An Lianbao WF-1 router has a command execution vulnerability, which can be exploited by attackers to gain server management rights
| VAR-202104-1263 | CVE-2021-30231 | An Lianbao WF-1 router has a command execution vulnerability |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
The api/zrDm/set_ZRElink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the bssaddr, abiaddr, devtoken, devid, elinksync, or elink_proc_enable parameter. Anlianbao WT-1 is a 4G router that integrates wired and wireless router access, and secure Internet access.
An Lianbao WF-1 router has a command execution vulnerability, which can be exploited by attackers to gain server management rights
| VAR-202104-1261 | CVE-2021-30229 | An Lianbao WF-1 router has a command execution vulnerability |
CVSS V2: 6.5 CVSS V3: 8.8 Severity: HIGH |
The api/zrDm/set_zrDm interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the dm_enable, AppKey, or Pwd parameter. Anlianbao WT-1 is a 4G router that integrates wired and wireless router access, and secure Internet access.
An Lianbao WF-1 router has a command execution vulnerability, which can be exploited by attackers to gain server management rights
| VAR-202104-1260 | CVE-2021-30228 | An Lianbao WF-1 router has a command execution vulnerability |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
The api/ZRAndlink/set_ZRAndlink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the iandlink_proc_enable parameter. Anlianbao WT-1 is a 4G router that integrates wired and wireless router access, and secure Internet access.
An Lianbao WF-1 router has a command execution vulnerability, which can be exploited by attackers to gain server management rights
| VAR-202102-1658 | CVE-2021-33962 | China Mobile An Lianbao WF-1 In the router OS Command injection vulnerability |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
China Mobile An Lianbao WF-1 router v1.0.1 is affected by an OS command injection vulnerability in the web interface /api/ZRUsb/pop_usb_device component. (DoS) It may be in a state. Anlianbao WT-1 is a 4G router that integrates wired and wireless router access, and secure Internet access.
An Lianbao WF-1 router has a command execution vulnerability, which can be exploited by attackers to gain server management rights
| VAR-202102-1657 | CVE-2021-33965 | China Mobile An Lianbao WF-1 Command injection vulnerability in router |
CVSS V2: 6.5 CVSS V3: 8.8 Severity: HIGH |
China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRMesh/set_ZRMesh which receives parameters by POST request, and the parameter mesh_enable and mesh_device have a command injection vulnerability. An attacker can use the vulnerability to execute remote commands. (DoS) It may be in a state. Anlianbao WT-1 is a 4G router that integrates wired and wireless router access, and secure Internet access.
An Lianbao WF-1 router has a command execution vulnerability, which can be exploited by attackers to gain server management rights