VARIoT IoT exploits database

Affected products: vendor, model and version
Type can be e.g: Remote Code Execution or Denial of Service
Look up free text in title and description

VAR-E-201812-0282 CVE-2018-4441
Sony Playstation 4 (PS4) < 6.20 - WebKit Code Execution (PoC) - Hardware local Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201904-1323
EDB ID: 46522
Sony Playstation 4 (PS4) < 6.20 - WebKit Code Execution (PoC). CVE-2018-4441 . local exploit for Hardware platform
VAR-E-201812-0097 No CVE Rockwell Automation Allen-Bradley PowerMonitor 1000 XSS No EDB ID
Rockwell Automation Allen-Bradley PowerMonitor 1000 suffers from a cross site scripting vulnerability.
VAR-E-201812-0198 CVE-2018-19616
Rockwell Automation Allen-Bradley PowerMonitor 1000 - Incorrect Access Control Authentication Bypass - Hardware webapps Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201812-0552
EDB ID: 45937
Rockwell Automation Allen-Bradley PowerMonitor 1000 - Incorrect Access Control Authentication Bypass. CVE-2018-19616 . webapps exploit for Hardware platform
VAR-E-201812-0167 CVE-2018-15716
CVE-2018-14933
NUUO NVRMini2 3.9.1 - (Authenticated) Command Injection - PHP webapps Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201811-0051, VAR-201808-0424
EDB ID: 45948
NUUO NVRMini2 3.9.1 - (Authenticated) Command Injection. CVE-2018-15716 . webapps exploit for PHP platform
VAR-E-201812-0105 No CVE Rockwell Automation Allen-Bradley PowerMonitor 1000 - Cross-Site Scripting - Hardware webapps Exploit EDB ID: 45928
Rockwell Automation Allen-Bradley PowerMonitor 1000 - Cross-Site Scripting.. webapps exploit for Hardware platform
VAR-E-201811-0193 CVE-2018-4386
Sony Playstation 4 (PS4) < 6.72 - WebKit Code Execution (PoC) - Hardware webapps Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201904-1440
EDB ID: 47893
Sony Playstation 4 (PS4) < 6.72 - WebKit Code Execution (PoC). CVE-2018-4386 . webapps exploit for Hardware platform
VAR-E-201811-0126 CVE-2017-6026
Schneider Electric PLC - Session Calculation Authentication Bypass - Hardware webapps Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201706-0456
EDB ID: 45918
Schneider Electric PLC - Session Calculation Authentication Bypass. CVE-2017-6026 . webapps exploit for Hardware platform
VAR-E-201811-0334 CVE-2017-13699
MOXA EDS-G512E CVE-2017-13699 Information Disclosure Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-201711-0914
No EDB ID
MOXA EDS-G512E is prone to an information-disclosure vulnerability. Successfully exploiting this issue may allow an attacker to obtain sensitive information that may aid in further attacks.
VAR-E-201811-0279 CVE-2018-15515
D-LINK Central WifiManager (CWM 100) 1.03 r0098 DLL Hijacking

Related entries in the VARIoT vulnerabilities database: VAR-201901-0599
No EDB ID
D-Link Central WiFiManager CWM-100 version 1.03 r0098 devices will load a trojan horse "quserex.dll" and will create a new thread running with SYSTEM integrity.
VAR-E-201811-0492 CVE-2018-15517
D-LINK Central WifiManager (CWM 100) 1.03 r0098 Server-Side Request Forgery

Related entries in the VARIoT vulnerabilities database: VAR-201901-0603
No EDB ID
Using a web browser or script server-side request forgery (SSRF) can be initiated against internal/external systems to conduct port scans by leveraging D-LINK's MailConnect component. The MailConnect feature on D-Link Central WiFiManager CWM-100 version 1.03 r0098 devices is intended to check a connection to an SMTP server but actually allows outbound TCP to any port on any IP address, leading to SSRF, as demonstrated by an index.php/System/MailConnect/host/127.0.0.1/port/22/secure/ URI. This can undermine accountability of where scan or connections actually came from and or bypass the FW etc. This can be automated via script or using Web Browser.
VAR-E-201811-0327 CVE-2018-15516
D-LINK Central WifiManager (CWM 100) 1.03 r0098 Man-In-The-Middle

Related entries in the VARIoT vulnerabilities database: VAR-201901-0600
No EDB ID
The FTP Server component of the D-LINK Central WifiManager can be used as a man-in-the-middle machine allowing PORT Command bounce scan attacks. This vulnerability allows remote attackers to abuse your network and discreetly conduct network port scanning. Victims will then think these scans are originating from the D-LINK network running the afflicted FTP Server and not you. Version 1.03 r0098 is affected.
VAR-E-201811-0024 CVE-2018-15705
CVE-2018-15707
Advantech WebAccess SCADA 8.3.2 - Remote Code Execution - ASP webapps Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201810-0131, VAR-201810-0129
EDB ID: 45774
Advantech WebAccess SCADA 8.3.2 - Remote Code Execution. CVE-2018-15707CVE-2018-15705 . webapps exploit for ASP platform
VAR-E-201811-0063 CVE-2018-18440
CVE-2018-18439
Das U-Boot Multiple Local Arbitrary Code Execution Vulnerabilities

Related entries in the VARIoT vulnerabilities database: VAR-201811-0057, VAR-201811-0056
No EDB ID
Das U-Boot is prone to multiple local arbitrary code-execution vulnerabilities. Attackers can exploit these issues to execute arbitrary code in the context of the U-Boot instance. Failed exploit attempts will likely cause a denial-of-service condition.
VAR-E-201810-0011 No CVE ZyXEL VMG3312-B10B < 1.00(AAPP.7) - Credential Disclosure Exploit No EDB ID
VAR-E-201810-0436 No CVE ZyXEL VMG3312-B10B Credential Disclosure No EDB ID
ZyXEL VMG3312-B10B versions prior to 1.00 (AAPP.7) suffer from a credential disclosure vulnerability.
VAR-E-201810-0176 No CVE ZyXEL VMG3312-B10B < 1.00(AAPP.7) - Credential Disclosure - Hardware dos Exploit EDB ID: 45746
ZyXEL VMG3312-B10B < 1.00(AAPP.7) - Credential Disclosure.. dos exploit for Hardware platform
VAR-E-201810-0630 No CVE D-Link DSL-2640T Cross Site Scripting No EDB ID
D-Link DSL-2640T suffers from a cross site scripting vulnerability.
VAR-E-201810-0504 CVE-2018-17534
Teltonika RUT9XX Missing Access Control To UART Root Terminal

Related entries in the VARIoT vulnerabilities database: VAR-201810-0457
No EDB ID
Teltonika RUT9XX routers with firmware before 00.04.233 provide a root terminal on a serial interface without proper access control. This allows attackers with physical access to execute arbitrary commands with root privileges.
VAR-E-201810-0556 No CVE Airties AIR5342 1.0.0.18 - Cross-Site Scripting Vulnerability No EDB ID
VAR-E-201809-0451 CVE-2018-17594
Airties AIR5442 1.0.0.18 Cross Site Scripting

Related entries in the VARIoT vulnerabilities database: VAR-201810-0507
No EDB ID
A cross site scripting vulnerability has been discovered in the AIR5443v2 modem of the AirTies manufacturer. AirTies Air 5443v2 devices have XSS via the top.html productboardtype parameter.