VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202103-1680 No CVE Skyworth home gateway smart terminal DT720-cs has a denial of service vulnerability CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
Skyworth Digital Co., Ltd. (hereinafter referred to as "Skyworth Digital") is a national high-tech enterprise focusing on providing comprehensive and systematic digital home solutions and services for global users. Skyworth home gateway smart terminal DT720-cs has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service attack.
VAR-202103-1681 No CVE Huawei HG8346M FTTH has a denial of service vulnerability CVSS V2: 3.3
CVSS V3: -
Severity: LOW
HG8346M is a Huawei router. Huawei HG8346M FTTH has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service attack.
VAR-202103-1682 No CVE MERCURY MR108GP-AC V2.0 has a denial of service vulnerability CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
MR108GP-AC is an enterprise-level router of Shenzhen Meikexing Communication Technology Co., Ltd. MERCURY MR108GP-AC V2.0 has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service attack.
VAR-202103-1683 No CVE MERCURY MR100GP-AC V2.0 has a denial of service vulnerability CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
MR100GP-AC is an enterprise-level router of Shenzhen Meikexing Communication Technology Co., Ltd. MERCURY MR100GP-AC V2.0 has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service attack.
VAR-202103-1686 No CVE MERCURY X188G has a denial of service vulnerability CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
X188G is a router. MERCURY X188G has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service attack.
VAR-202103-1688 No CVE TP-Link TL-R479G has a denial of service vulnerability CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
TL-R479G is an enterprise VPN router of Prolink Technology Co., Ltd. TP-Link TL-R479G has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service attack.
VAR-202103-1689 No CVE TP-Link TL-XDR5430 has a denial of service vulnerability CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
TL-XDR5430 is a router of TP-Link. TP-Link TL-XDR5430 has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service attack.
VAR-202103-0226 CVE-2020-28466 nats-server  Vulnerability in CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
This affects all versions of package github.com/nats-io/nats-server/server. Untrusted accounts are able to crash the server using configs that represent a service export/import cycles. Disclaimer from the maintainers: Running a NATS service which is exposed to untrusted users presents a heightened risk. Any remote execution flaw or equivalent seriousness, or denial-of-service by unauthenticated users, will lead to prompt releases by the NATS maintainers. Fixes for denial of service issues with no threat of remote execution, when limited to account holders, are likely to just be committed to the main development branch with no special attention. Those who are running such services are encouraged to build regularly from git. nats-server Contains an unspecified vulnerability.Denial of service (DoS) It may be put into a state
VAR-202103-0661 CVE-2020-5014 IBM DataPower Gateway  Server-side request forgery vulnerability in CVSS V2: 4.6
CVSS V3: 6.7
Severity: MEDIUM
IBM DataPower Gateway V10 and V2018 could allow a local attacker with administrative privileges to execute arbitrary code on the system using a server-side requesr forgery attack. IBM X-Force ID: 193247. IBM DataPower Gateway Contains a server-side request forgery vulnerability. Vendor exploits this vulnerability IBM X-Force ID: 193247 It is published as.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be put into a state. IBM DataPower Gateway is a security and integration platform specially designed for mobile, cloud, application programming interface (API), network, service-oriented architecture (SOA), B2B and cloud workloads. The platform secures, integrates and optimizes access across channels with a dedicated gateway platform
VAR-202103-1684 No CVE Huawei-China Telecom GPON/EPON routers have arbitrary file download vulnerabilities CVSS V2: 1.4
CVSS V3: -
Severity: LOW
Founded in 1987, Huawei is a provider of ICT (information and communications) infrastructure and smart terminals. The Huawei-China Telecom GPON/EPON router integrated machine has arbitrary file download vulnerabilities. Attackers can use vulnerabilities to obtain sensitive information.
VAR-202103-1685 No CVE Multiple LB-LINK routers have logic vulnerabilities CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
BL-X22, BL-X16 and BL-X12 are all wireless routers of Shenzhen Bilian Electronics Co., Ltd. Many LB-LINK routers have logic loopholes. Attackers can use vulnerabilities to modify user passwords, wifi passwords and other information.
VAR-202103-1687 No CVE Excitel SY-GPON-1110-WADONT has an information disclosure vulnerability CVSS V2: 6.4
CVSS V3: -
Severity: MEDIUM
SY-GPON-1110-WADONT is a router. Excitel SY-GPON-1110-WADONT has an information disclosure vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202103-1690 No CVE Suraaj Computer RL801GW has an information disclosure vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
RL801GW is a network device. Suraaj Computer RL801GW has an information disclosure vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202103-1691 No CVE Inhantong InRouter900 industrial router has an arbitrary file deletion vulnerability (CNVD-2021-10443) CVSS V2: 4.0
CVSS V3: -
Severity: MEDIUM
Inhantong InRouter900 series industrial routers are 4G industrial routers. Inhantong InRouter900 industrial router has an arbitrary file deletion vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to delete arbitrary files.
VAR-202103-1692 No CVE Inhantong InRouter900 industrial router has a command execution vulnerability (CNVD-2021-10446) CVSS V2: 9.0
CVSS V3: -
Severity: HIGH
Inhantong InRouter900 series industrial routers are 4G industrial routers. Inhantong InRouter900 industrial router has a command execution vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to execute arbitrary commands on the system.
VAR-202103-1693 No CVE Inhantong InRouter900 industrial router has an arbitrary file deletion vulnerability (CNVD-2021-10444) CVSS V2: 4.0
CVSS V3: -
Severity: MEDIUM
Inhantong InRouter900 series industrial routers are 4G industrial routers. Inhantong InRouter900 industrial router has an arbitrary file deletion vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to delete arbitrary files.
VAR-202103-1694 No CVE Inhantong InRouter900 industrial router has command execution vulnerability (CNVD-2021-10445) CVSS V2: 9.0
CVSS V3: -
Severity: HIGH
Inhantong InRouter900 series industrial routers are 4G industrial routers. Inhantong InRouter900 industrial router has a command execution vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to execute arbitrary commands on the system.
VAR-202103-1695 No CVE Inhantong InRouter900 industrial router has command execution vulnerability (CNVD-2021-10447) CVSS V2: 9.0
CVSS V3: -
Severity: HIGH
Inhantong InRouter900 series industrial routers are 4G industrial routers. Inhantong InRouter900 industrial router has a command execution vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to execute arbitrary commands on the system.
VAR-202103-1696 No CVE Inhantong InRouter900 industrial router has arbitrary file reading vulnerabilities CVSS V2: 4.0
CVSS V3: -
Severity: MEDIUM
Inhantong InRouter900 series industrial routers are 4G industrial routers. Inhantong InRouter900 industrial router has an arbitrary file reading vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to read arbitrary files.
VAR-202103-1697 No CVE Inhantong InRouter900 industrial router has arbitrary file deletion vulnerability CVSS V2: 4.0
CVSS V3: -
Severity: MEDIUM
Inhantong InRouter900 series industrial routers are 4G industrial routers. Inhantong InRouter900 industrial router has an arbitrary file deletion vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to delete arbitrary files.