VARIoT IoT vulnerabilities database
| VAR-202103-1680 | No CVE | Skyworth home gateway smart terminal DT720-cs has a denial of service vulnerability |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
Skyworth Digital Co., Ltd. (hereinafter referred to as "Skyworth Digital") is a national high-tech enterprise focusing on providing comprehensive and systematic digital home solutions and services for global users.
Skyworth home gateway smart terminal DT720-cs has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service attack.
| VAR-202103-1681 | No CVE | Huawei HG8346M FTTH has a denial of service vulnerability |
CVSS V2: 3.3 CVSS V3: - Severity: LOW |
HG8346M is a Huawei router.
Huawei HG8346M FTTH has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service attack.
| VAR-202103-1682 | No CVE | MERCURY MR108GP-AC V2.0 has a denial of service vulnerability |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
MR108GP-AC is an enterprise-level router of Shenzhen Meikexing Communication Technology Co., Ltd.
MERCURY MR108GP-AC V2.0 has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service attack.
| VAR-202103-1683 | No CVE | MERCURY MR100GP-AC V2.0 has a denial of service vulnerability |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
MR100GP-AC is an enterprise-level router of Shenzhen Meikexing Communication Technology Co., Ltd.
MERCURY MR100GP-AC V2.0 has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service attack.
| VAR-202103-1686 | No CVE | MERCURY X188G has a denial of service vulnerability |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
X188G is a router.
MERCURY X188G has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service attack.
| VAR-202103-1688 | No CVE | TP-Link TL-R479G has a denial of service vulnerability |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
TL-R479G is an enterprise VPN router of Prolink Technology Co., Ltd.
TP-Link TL-R479G has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service attack.
| VAR-202103-1689 | No CVE | TP-Link TL-XDR5430 has a denial of service vulnerability |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
TL-XDR5430 is a router of TP-Link.
TP-Link TL-XDR5430 has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service attack.
| VAR-202103-0226 | CVE-2020-28466 | nats-server Vulnerability in |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
This affects all versions of package github.com/nats-io/nats-server/server. Untrusted accounts are able to crash the server using configs that represent a service export/import cycles. Disclaimer from the maintainers: Running a NATS service which is exposed to untrusted users presents a heightened risk. Any remote execution flaw or equivalent seriousness, or denial-of-service by unauthenticated users, will lead to prompt releases by the NATS maintainers. Fixes for denial of service issues with no threat of remote execution, when limited to account holders, are likely to just be committed to the main development branch with no special attention. Those who are running such services are encouraged to build regularly from git. nats-server Contains an unspecified vulnerability.Denial of service (DoS) It may be put into a state
| VAR-202103-0661 | CVE-2020-5014 | IBM DataPower Gateway Server-side request forgery vulnerability in |
CVSS V2: 4.6 CVSS V3: 6.7 Severity: MEDIUM |
IBM DataPower Gateway V10 and V2018 could allow a local attacker with administrative privileges to execute arbitrary code on the system using a server-side requesr forgery attack. IBM X-Force ID: 193247. IBM DataPower Gateway Contains a server-side request forgery vulnerability. Vendor exploits this vulnerability IBM X-Force ID: 193247 It is published as.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be put into a state. IBM DataPower Gateway is a security and integration platform specially designed for mobile, cloud, application programming interface (API), network, service-oriented architecture (SOA), B2B and cloud workloads. The platform secures, integrates and optimizes access across channels with a dedicated gateway platform
| VAR-202103-1684 | No CVE | Huawei-China Telecom GPON/EPON routers have arbitrary file download vulnerabilities |
CVSS V2: 1.4 CVSS V3: - Severity: LOW |
Founded in 1987, Huawei is a provider of ICT (information and communications) infrastructure and smart terminals.
The Huawei-China Telecom GPON/EPON router integrated machine has arbitrary file download vulnerabilities. Attackers can use vulnerabilities to obtain sensitive information.
| VAR-202103-1685 | No CVE | Multiple LB-LINK routers have logic vulnerabilities |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
BL-X22, BL-X16 and BL-X12 are all wireless routers of Shenzhen Bilian Electronics Co., Ltd.
Many LB-LINK routers have logic loopholes. Attackers can use vulnerabilities to modify user passwords, wifi passwords and other information.
| VAR-202103-1687 | No CVE | Excitel SY-GPON-1110-WADONT has an information disclosure vulnerability |
CVSS V2: 6.4 CVSS V3: - Severity: MEDIUM |
SY-GPON-1110-WADONT is a router.
Excitel SY-GPON-1110-WADONT has an information disclosure vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202103-1690 | No CVE | Suraaj Computer RL801GW has an information disclosure vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
RL801GW is a network device.
Suraaj Computer RL801GW has an information disclosure vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202103-1691 | No CVE | Inhantong InRouter900 industrial router has an arbitrary file deletion vulnerability (CNVD-2021-10443) |
CVSS V2: 4.0 CVSS V3: - Severity: MEDIUM |
Inhantong InRouter900 series industrial routers are 4G industrial routers.
Inhantong InRouter900 industrial router has an arbitrary file deletion vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to delete arbitrary files.
| VAR-202103-1692 | No CVE | Inhantong InRouter900 industrial router has a command execution vulnerability (CNVD-2021-10446) |
CVSS V2: 9.0 CVSS V3: - Severity: HIGH |
Inhantong InRouter900 series industrial routers are 4G industrial routers.
Inhantong InRouter900 industrial router has a command execution vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to execute arbitrary commands on the system.
| VAR-202103-1693 | No CVE | Inhantong InRouter900 industrial router has an arbitrary file deletion vulnerability (CNVD-2021-10444) |
CVSS V2: 4.0 CVSS V3: - Severity: MEDIUM |
Inhantong InRouter900 series industrial routers are 4G industrial routers.
Inhantong InRouter900 industrial router has an arbitrary file deletion vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to delete arbitrary files.
| VAR-202103-1694 | No CVE | Inhantong InRouter900 industrial router has command execution vulnerability (CNVD-2021-10445) |
CVSS V2: 9.0 CVSS V3: - Severity: HIGH |
Inhantong InRouter900 series industrial routers are 4G industrial routers.
Inhantong InRouter900 industrial router has a command execution vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to execute arbitrary commands on the system.
| VAR-202103-1695 | No CVE | Inhantong InRouter900 industrial router has command execution vulnerability (CNVD-2021-10447) |
CVSS V2: 9.0 CVSS V3: - Severity: HIGH |
Inhantong InRouter900 series industrial routers are 4G industrial routers.
Inhantong InRouter900 industrial router has a command execution vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to execute arbitrary commands on the system.
| VAR-202103-1696 | No CVE | Inhantong InRouter900 industrial router has arbitrary file reading vulnerabilities |
CVSS V2: 4.0 CVSS V3: - Severity: MEDIUM |
Inhantong InRouter900 series industrial routers are 4G industrial routers.
Inhantong InRouter900 industrial router has an arbitrary file reading vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to read arbitrary files.
| VAR-202103-1697 | No CVE | Inhantong InRouter900 industrial router has arbitrary file deletion vulnerability |
CVSS V2: 4.0 CVSS V3: - Severity: MEDIUM |
Inhantong InRouter900 series industrial routers are 4G industrial routers.
Inhantong InRouter900 industrial router has an arbitrary file deletion vulnerability. The vulnerability is caused by the program's failure to correctly verify user data. Remote attackers can use malicious HTTP requests to use this vulnerability to delete arbitrary files.