VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202103-0225 CVE-2020-28346 ACRN  In  NULL  Pointer dereference vulnerability CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
ACRN through 2.2 has a devicemodel/hw/pci/virtio/virtio.c NULL Pointer Dereference. ACRN is an open source virtual machine monitor for the Internet of Things. No detailed vulnerability details are currently provided
VAR-202103-0234 CVE-2020-28695 Askey Fiber Router RTF3505VW-N1 BR_SV_g000_R3505VWN1001_s32_7  device   Code injection vulnerabilities CVSS V2: 8.3
CVSS V3: 8.8
Severity: HIGH
Askey Fiber Router RTF3505VW-N1 BR_SV_g000_R3505VWN1001_s32_7 devices allow Remote Code Execution and retrieval of admin credentials to log into the Dashboard or login via SSH, leading to code execution as root. Askey Fiber Router RTF3505VW-N1 BR_SV_g000_R3505VWN1001_s32_7 device Contains a code injection vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Askey is the world's largest professional manufacturer of international network communication equipment, and its main products include ADSL and Cable Modem, ADSL Router, Cable Router, etc. Askey fiber router unauthorized RCE vulnerability, unauthorized remote attackers can use this vulnerability to execute arbitrary commands on the target device
VAR-202103-0896 CVE-2021-27276 NETGEAR ProSAFE Network Management System  Traversal Vulnerability in Japan CVSS V2: 5.5
CVSS V3: 7.1
Severity: HIGH
This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the MibController class. When parsing the realName parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-12122. Zero Day Initiative To this vulnerability ZDI-CAN-12122 Was numbered.Information is tampered with and denial of service (DoS) It may be put into a state. Netgear NETGEAR is a router made by Netgear. A hardware device that connects two or more networks, acting as a gateway between the networks
VAR-202103-0895 CVE-2021-27275 NETGEAR ProSAFE Network Management System  Traversal Vulnerability in Japan CVSS V2: 6.5
CVSS V3: 8.3
Severity: HIGH
This vulnerability allows remote attackers to disclose sensitive information and delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the ConfigFileController class. When parsing the realName parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose sensitive information or to create a denial-of-service condition on the system. Was ZDI-CAN-12125. NETGEAR ProSAFE Network Management System Contains a path traversal vulnerability. Zero Day Initiative To this vulnerability ZDI-CAN-12125 Was numbered.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Netgear NETGEAR is a router made by Netgear. A hardware device that connects two or more networks, acting as a gateway between the networks
VAR-202103-0892 CVE-2021-27272 NETGEAR ProSAFE Network Management System  Traversal Vulnerability in Japan CVSS V2: 7.5
CVSS V3: 7.1
Severity: HIGH
This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the ReportTemplateController class. When parsing the path parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-12123. Zero Day Initiative To this vulnerability ZDI-CAN-12123 Was numbered.Information is tampered with and denial of service (DoS) It may be put into a state
VAR-202103-0894 CVE-2021-27274 NETGEAR ProSAFE Network Management System  Unlimited Upload Vulnerability in File Vulnerability CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Authentication is not required to exploit this vulnerability. The specific flaw exists within the MFileUploadController class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-12124. Zero Day Initiative To this vulnerability ZDI-CAN-12124 Was numbered.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Netgear NETGEAR is a router made by Netgear. A hardware device that connects two or more networks, acting as a gateway between the networks
VAR-202103-0893 CVE-2021-27273 NETGEAR ProSAFE Network Management System  In  OS  Command injection vulnerability CVSS V2: 9.0
CVSS V3: 8.8
Severity: HIGH
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the SettingConfigController class. When parsing the fileName parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-12121. Zero Day Initiative To this vulnerability ZDI-CAN-12121 Was numbered.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Netgear NETGEAR is a router made by Netgear. A hardware device that connects two or more networks, acting as a gateway between the networks
VAR-202103-0650 CVE-2021-21396 wire-server  Information Disclosure Vulnerability CVSS V2: 4.0
CVSS V3: 6.5
Severity: MEDIUM
wire-server is an open-source back end for Wire, a secure collaboration platform. In wire-server from version 2021-02-16 and before version 2021-03-02, the client metadata of all users was exposed in the `GET /users/list-clients` endpoint. The endpoint could be used by any logged in user who could request client details of any other user (no connection required) as far as they can find their User ID. The exposed metadata included id, class, type, location, time, and cookie. A user on a Wire backend could use this endpoint to find registration time and location for each device for a given list of users. As a workaround, remove `/list-clients` from nginx config. This has been fixed in version 2021-03-02. wire-server Contains an information disclosure vulnerability.Information may be obtained
VAR-202103-1332 CVE-2021-25372 DSP driver  Out-of-bounds Vulnerability in Microsoft CVSS V2: 7.2
CVSS V3: 6.7
Severity: MEDIUM
An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access. DSP driver Is vulnerable to an out-of-bounds write.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Samsung DSP driver is a digital signal processing driver for Samsung mobile devices. Samsung DSP driver has an out-of-bounds write vulnerability, which is caused by incorrect boundary checking. Attackers can exploit this vulnerability to perform out-of-bounds memory access
VAR-202103-1754 No CVE A weak password vulnerability exists in the transcoding server configuration management system of Zhejiang Univision Technology Co., Ltd. CVSS V2: 6.4
CVSS V3: -
Severity: MEDIUM
Zhejiang Yushi Technology Co., Ltd. (abbreviated as: Yushi) was founded in 2011 and is a global public safety and intelligent transportation solution provider. Zhejiang Univision Technology Co., Ltd.'s transcoding server configuration management system has a weak password vulnerability. Attackers can use this vulnerability to log in to the background without authorization.
VAR-202103-1778 No CVE 360 smart camera PTZ AI version standard AP2C has unauthorized access vulnerability CVSS V2: 6.4
CVSS V3: -
Severity: MEDIUM
The 360 smart camera PTZ AI version standard AP2C is a device under the 360 smart home platform, which can help the owner realize real-time monitoring of the home situation. The 360 smart camera PTZ AI version standard AP2C has an unauthorized access vulnerability. Attackers can use this vulnerability to initiate control operations belonging to high-level shared users, such as switching the camera, setting the volume, and setting the AI function.
VAR-202103-1779 No CVE Mobaibox network set-top box has logic flaws and vulnerabilities CVSS V2: 6.4
CVSS V3: -
Severity: MEDIUM
The business scope of China Mobile Communications Co., Ltd. includes: IP telephony business; Internet access service business, Internet backbone network data transmission business; engaged in the design of mobile communications, IP telephony, and Internet networks. The Mobaibox network set-top box has a logic flaw vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202103-1780 No CVE Xiaoxing sees the unauthorized access vulnerability of smart cameras CVSS V2: 5.5
CVSS V3: -
Severity: MEDIUM
Look at Xiaoxing. Smart cameras are important devices under the ZTE Smart Home Platform, which can help owners realize real-time monitoring of family conditions. Xiaoxing sees that there is an unauthorized access vulnerability in smart cameras. Attackers can use the vulnerability to obtain sensitive information and perform unauthorized operations.
VAR-202103-1807 No CVE DS-8116HWS-SH and DS-7804N-E1/4N have weak password vulnerabilities CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Hikvision is a video-centric intelligent IoT solution and big data service provider. DS-8116HWS-SH and DS-7804N-E1/4N have weak password vulnerabilities, which can be exploited by attackers to obtain sensitive information.
VAR-202103-1808 CVE-2025-34058 A weak password vulnerability exists in the streaming media management server of Hangzhou Hikvision System Technology Co., Ltd. CVSS V2: 5.0
CVSS V3: -
Severity: High
Hikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote attackers to authenticate and access restricted functionality. After authenticating with these credentials, an attacker can exploit an arbitrary file read vulnerability in the /systemLog/downFile.php endpoint via directory traversal in the fileName parameter. This exploit chain can enable unauthorized access to sensitive system files. Hikvision is a video-centric intelligent IoT solution and big data service provider. The streaming media management server of Hangzhou Hikvision System Technology Co., Ltd. has a weak password vulnerability. Attackers can use the vulnerability to obtain sensitive information
VAR-202103-0582 CVE-2020-6771 Bosch IP Helper  Vulnerability in Uncontrolled Search Path Elements CVSS V2: 6.9
CVSS V3: 7.8
Severity: HIGH
Loading a DLL through an Uncontrolled Search Path Element in Bosch IP Helper up to and including version 1.00.0008 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious DLL in the same application directory as the portable IP Helper application. Bosch IP Helper is an industrial control equipment of Bosch company in Germany. Universal discovery and network configuration tool for all Bosch IP Network Video products
VAR-202103-1321 CVE-2021-25355 Samsung Notes  Inappropriate Default Permission Vulnerability CVSS V2: 4.6
CVSS V3: 7.8
Severity: High
Using unsafe PendingIntent in Samsung Notes prior to version 4.2.00.22 allows local attackers unauthorized action without permission via hijacking the PendingIntent. Samsung Notes Is vulnerable to incorrect default permissions.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state
VAR-202103-0583 CVE-2020-6785 Bosch BVMS  and  BVMS Viewer  Vulnerability in Uncontrolled Search Path Elements CVSS V2: 6.9
CVSS V3: 7.8
Severity: HIGH
Loading a DLL through an Uncontrolled Search Path Element in Bosch BVMS and BVMS Viewer in versions 10.1.0, 10.0.1, 10.0.0 and 9.0.0 and older potentially allows an attacker to execute arbitrary code on a victim's system. This affects both the installer as well as the installed application. This also affects Bosch DIVAR IP 7000 R2, Bosch DIVAR IP all-in-one 5000 and Bosch DIVAR IP all-in-one 7000 with installers and installed BVMS versions prior to BVMS 10.1.1. Bosch BVMS and BVMS Viewer There is a vulnerability in an element of an uncontrolled search path.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state
VAR-202103-0588 CVE-2020-6790 Bosch Video Streaming Gateway  Vulnerability in Uncontrolled Search Path Elements CVSS V2: 6.9
CVSS V3: 7.8
Severity: HIGH
Calling an executable through an Uncontrolled Search Path Element in the Bosch Video Streaming Gateway installer up to and including version 6.45.10 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious exe in the same directory where the installer is started from. Bosch BVMS is an application system of Bosch Company in Germany. For video management. A security vulnerability exists in Bosch BVMS that could allow an attacker to execute arbitrary code on a victim's system
VAR-202103-1327 CVE-2021-25367 Samsung Notes  Traversal Vulnerability in Japan CVSS V2: 5.5
CVSS V3: 5.4
Severity: Medium
Path Traversal vulnerability in Samsung Notes prior to version 4.2.00.22 allows attackers to access local files without permission