VARIoT IoT exploits database

VAR-E-201907-0200 |
CVE-2019-1010156 CVE-2019-1010155 |
D-Link DSL-2750U Multiple Authentication Bypass Vulnerabilities
Related entries in the VARIoT vulnerabilities database: VAR-201907-1179, VAR-201907-1180 | No EDB ID |
D-Link DSL-2750U is prone to multiple authentication-bypass vulnerabilities.
An attacker can exploit these issues to bypass authentication mechanism and perform unauthorized actions. This may lead to further attacks.
D-Link DSL-2750U Router 1.11 is vulnerable; other versions may also be affected.
VAR-E-201907-0018 |
CVE-2019-1943 |
CISCO Small Business 200 / 300 / 500 Switches - Multiple Vulnerabilities - Hardware webapps Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201907-0394 | EDB ID: 47118 |
CISCO Small Business 200 / 300 / 500 Switches - Multiple Vulnerabilities. CVE-2019-1943 . webapps exploit for Hardware platform
VAR-E-201907-0037 |
CVE-2019-13482 CVE-2019-13481 |
D-Link DIR-818LW Multiple Command Injection Vulnerabilities
Related entries in the VARIoT vulnerabilities database: VAR-201907-0708, VAR-201907-0707 | No EDB ID |
D-Link DIR-818LW is prone to multiple command-injection vulnerabilities.
Exploiting these issues could allow an attacker to execute arbitrary commands in the context of the affected device. Failed exploit attempts will likely result in denial-of-service conditions.
D-Link DIR-818LW devices with firmware 2.06betab01 are vulnerable.
VAR-E-201907-0133 | No CVE | Siemens TIA Portal - Remote Command Execution - Hardware remote Exploit | EDB ID: 47083 |
Siemens TIA Portal - Remote Command Execution.. remote exploit for Hardware platform
VAR-E-201907-0172 | No CVE | Huawei HG530 Cross Site Request Forgery | No EDB ID |
Huawei HG530 suffers from a cross site request forgery vulnerability.
VAR-E-201907-0024 |
CVE-2019-0285 |
SAP Crystal Reports - Information Disclosure - Multiple webapps Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201904-1088 | EDB ID: 47061 |
SAP Crystal Reports - Information Disclosure. CVE-2019-0285 . webapps exploit for Multiple platform
VAR-E-201906-0016 |
CVE-2019-5017 |
KCodes NetUSB CVE-2019-5017 Information Disclosure Vulnerability
Related entries in the VARIoT vulnerabilities database: VAR-201906-0193 | No EDB ID |
KCodes NetUSB is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to obtain sensitive information that may aid in further attacks.
KCodes NetUSB.ko versions 1.0.2.66 and 1.0.2.69 are vulnerable; other versions may also be affected.
VAR-E-201906-0085 |
CVE-2019-5016 |
KCodes NetUSB CVE-2019-5016 Memory Corruption Vulnerability
Related entries in the VARIoT vulnerabilities database: VAR-201906-0192 | No EDB ID |
KCodes NetUSB is prone to a memory-corruption vulnerability.
Attackers can exploit this issue to obtain sensitive information or crash the application resulting in a denial-of-service condition.
KCodes NetUSB.ko versions 1.0.2.66 and 1.0.2.69 are vulnerable; other versions may also be affected.
VAR-E-201906-0001 |
CVE-2019-7228 CVE-2019-7227 CVE-2019-7231 CVE-2019-7226 CVE-2019-7232 CVE-2019-7230 |
ABB IDAL HTTP Server Authentication Bypass
Related entries in the VARIoT vulnerabilities database: VAR-201906-0222, VAR-201906-0218, VAR-201906-0216, VAR-201906-0221, VAR-201906-0217, VAR-201906-0220 | No EDB ID |
The IDAL HTTP server CGI interface contains a URL, which allows an unauthenticated attacker to bypass authentication and gain access to privileged functions. In the IDAL CGI interface, there is a URL (/cgi/loginDefaultUser), which will create a session in an authenticated state and return the session ID along with the username and plaintext password of the user. An attacker can then login with the provided credentials or supply the string 'IDALToken=......' in a cookie which will allow them to perform privileged operations such as restarting the service with /cgi/restart.
VAR-E-201906-0167 |
CVE-2019-12789 |
Telus Actiontec T2200H Local Privilege Escalation
Related entries in the VARIoT vulnerabilities database: VAR-201906-0591 | No EDB ID |
Telus Actiontec T2200H with firmware T2200H-31.128L.08 suffers from a local privilege escalation vulnerability.
VAR-E-201906-0133 |
CVE-2019-3946 CVE-2019-3947 |
Fuji Electric V-Server Multiple Security Vulnerabilities
Related entries in the VARIoT vulnerabilities database: VAR-201906-0327, VAR-201906-0328 | No EDB ID |
Fuji Electric V-Server is prone to multiple security vulnerabilities:
1. A remote denial-of-service vulnerability
2. An information disclosure vulnerability
An attacker can exploit these issues to cause a denial-of-service condition or obtain sensitive information that may lead to further attacks .
Versions prior to V-SFT 6.0.33.0 are vulnerable.
VAR-E-201906-0173 |
CVE-2019-0174 |
DRAM CVE-2019-0174 Local Information Disclosure Vulnerability
Related entries in the VARIoT vulnerabilities database: VAR-201906-0918 | No EDB ID |
DRAM is prone to an information disclosure vulnerability.
A local attacker may leverage this issue to gain sensitive information from the physical address space.
VAR-E-201906-0081 |
CVE-2017-8404 CVE-2017-8405 CVE-2017-8406 CVE-2017-8407 CVE-2017-8408 CVE-2017-8409 CVE-2017-8410 CVE-2017-8411 CVE-2017-8412 CVE-2017-8413 CVE-2017-8414 CVE-2017-8415 CVE-2017-8416 CVE-2017-8417 |
Dlink DCS-1130 Command Injection / CSRF / Stack Overflow
Related entries in the VARIoT vulnerabilities database: VAR-201907-1073, VAR-201907-1077, VAR-201907-1072, VAR-201907-1070, VAR-201907-1064, VAR-201907-1075, VAR-201907-1068, VAR-201907-1069, VAR-201907-1071, VAR-201907-1066, VAR-201907-1074, VAR-201907-1065, VAR-201907-1076, VAR-201907-1067 | No EDB ID |
Dlink DCS-1130 suffers from command injection, cross site request forgery, stack overflow, and various other vulnerabilities.
VAR-E-201906-0039 |
CVE-2017-8328 CVE-2017-8329 CVE-2017-8330 CVE-2017-8331 CVE-2017-8332 CVE-2017-8333 CVE-2017-8334 CVE-2017-8335 CVE-2017-8336 CVE-2017-8337 |
Securifi Almond 2015 Buffer Overflow / Command Injection / XSS / CSRF
Related entries in the VARIoT vulnerabilities database: VAR-201906-0769, VAR-201906-0772, VAR-201906-0773, VAR-201906-0776, VAR-201906-0775, VAR-201906-0770, VAR-201906-0774, VAR-201906-0777, VAR-201906-0778, VAR-201906-0771 | No EDB ID |
Securifi Almond 2015 suffers from buffer overflow, command injection, cross site scripting, cross site request forgery, and various other vulnerabilities.
VAR-E-201906-0064 |
CVE-2017-13719 CVE-2017-8226 CVE-2017-8227 CVE-2017-8228 CVE-2017-8229 CVE-2017-8230 |
Amcrest IPM-721S Credential Disclosure / Privilege Escalation
Related entries in the VARIoT vulnerabilities database: VAR-201907-1080, VAR-201907-1081, VAR-201907-1079, VAR-201907-1078, VAR-201907-1082, VAR-201907-1046 | No EDB ID |
Amcrest IPM-721S suffers from credential disclosure, privilege escalation, and a long list of other vulnerabilities.
VAR-E-201906-0083 |
CVE-2018-19864 |
NUUO NVRMini 2 3.9.1 - 'sscanf' Stack Overflow - Hardware remote Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201812-1058 | EDB ID: 46960 |
NUUO NVRMini 2 3.9.1 - 'sscanf' Stack Overflow. CVE-2018-19864 . remote exploit for Hardware platform
VAR-E-201905-0230 |
CVE-2019-12195 |
TP-LINK TL-WR840N v5 00000005 - Cross-Site Scripting - Hardware webapps Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201905-1254 | EDB ID: 46882 |
TP-LINK TL-WR840N v5 00000005 - Cross-Site Scripting. CVE-2019-12195 . webapps exploit for Hardware platform
VAR-E-201905-0120 |
CVE-2014-9418 |
Huawei eSpace 1.1.11.103 - 'ContactsCtrl.dll' / 'eSpaceStatusCtrl.dll' ActiveX Heap Overflow - Windows dos Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201412-0110 | EDB ID: 46868 |
Huawei eSpace 1.1.11.103 - 'ContactsCtrl.dll' / 'eSpaceStatusCtrl.dll' ActiveX Heap Overflow. CVE-2014-9418 . dos exploit for Windows platform
VAR-E-201905-0207 |
CVE-2014-9417 |
Huawei eSpace 1.1.11.103 - Image File Format Handling Buffer Overflow - Windows dos Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201412-0109 | EDB ID: 46867 |
Huawei eSpace 1.1.11.103 - Image File Format Handling Buffer Overflow. CVE-2014-9417 . dos exploit for Windows platform
VAR-E-201905-0010 |
CVE-2014-9416 |
Huawei eSpace 1.1.11.103 - DLL Hijacking - Windows local Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201412-0108 | EDB ID: 46866 |
Huawei eSpace 1.1.11.103 - DLL Hijacking. CVE-2014-9416 . local exploit for Windows platform