VARIoT news about IoT security

Trust: 4.75

Fetched: Oct. 26, 2025, 9:42 a.m., Published: Oct. 21, 2025, 2:42 a.m.
Vulnerabilities: improper access control, access control flaw, privilege escalation
Affected productsExternal IDs
db: NVD ids: CVE-2025-33073
Related entries in the VARIoT vulnerabilities database: VAR-202109-1875

Trust: 6.0

Fetched: Oct. 26, 2025, 9:42 a.m., Published: Sept. 15, 2021, 10:15 p.m.
Vulnerabilities: authentication bypass
Affected productsExternal IDs
vendor: dahua model: camera
vendor: dahua model: ip camera
db: NVD ids: CVE-2021-33044

Trust: 3.0

Fetched: Oct. 26, 2025, 9:41 a.m., Published: Oct. 24, 2025, midnight
Vulnerabilities: code execution
Affected productsExternal IDs

Trust: 6.25

Fetched: Oct. 26, 2025, 9:41 a.m., Published: Oct. 11, 2025, 9:18 a.m.
Vulnerabilities: buffer overflow
Affected productsExternal IDs
vendor: huawei model: huawei
db: NVD ids: CVE-2025-58301

Trust: 5.25

Fetched: Oct. 26, 2025, 9:41 a.m., Published: Oct. 24, 2025, 11:04 a.m.
Vulnerabilities: authentication bypass, injection attack, buffer overflow...
Affected productsExternal IDs
vendor: samsung model: galaxy
vendor: samsung model: samsung galaxy
vendor: samsung model: printers
vendor: samsung model: samsung
vendor: samsung model: printer
vendor: samsung model: mobile
vendor: samsung model: mobile devices
vendor: google model: home
vendor: lexmark model: lexmark
vendor: lexmark model: printer
vendor: philips model: hue bridge
vendor: philips hue model: hue bridge

Trust: 4.25

Fetched: Oct. 26, 2025, 9:40 a.m., Published: Feb. 26, 2048, midnight
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2025-59287

Trust: 4.25

Fetched: Oct. 26, 2025, 9:40 a.m., Published: Oct. 24, 2025, 10:38 a.m.
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2025-59287

Trust: 4.75

Fetched: Oct. 26, 2025, 9:39 a.m., Published: Oct. 21, 2025, midnight
Vulnerabilities: denial of service, information disclosure, code execution
Affected productsExternal IDs
db: NVD ids: CVE-2022-38102, CVE-2025-23281, CVE-2022-36392, CVE-2025-23288, CVE-2025-23286, CVE-2025-23276

Trust: 5.5

Fetched: Oct. 26, 2025, 9:38 a.m., Published: Jan. 10, 2023, midnight
Vulnerabilities: denial of service
Affected productsExternal IDs
vendor: siemens model: ruggedcom
vendor: siemens model: rsl910
vendor: siemens model: ruggedcom ros
db: NVD ids: CVE-2025-41224, CVE-2025-41223, CVE-2023-52236, CVE-2025-41222
Related entries in the VARIoT vulnerabilities database: VAR-202406-0858

Trust: 4.75

Fetched: Oct. 26, 2025, 9:37 a.m., Published: Oct. 23, 2025, 10:05 p.m.
Vulnerabilities: command injection, code execution
Affected productsExternal IDs
vendor: tp-link model: routers
db: NVD ids: CVE-2025-7850, CVE-2024-21827, CVE-2025-7851

Trust: 4.75

Fetched: Oct. 24, 2025, 9:29 a.m., Published: Oct. 20, 2025, midnight
Vulnerabilities: denial of service
Affected productsExternal IDs
vendor: samsung model: samsung
vendor: samsung model: samsung mobile
vendor: samsung model: exynos
vendor: samsung model: mobile
db: NVD ids: CVE-2025-26781

Trust: 4.75

Fetched: Oct. 24, 2025, 9:29 a.m., Published: Oct. 7, 2025, midnight
Vulnerabilities: authorization vulnerability, command injection
Affected productsExternal IDs
db: NVD ids: CVE-2025-9133, CVE-2025-8078

Trust: 3.25

Fetched: Oct. 24, 2025, 9:29 a.m., Published: Oct. 22, 2025, 3:01 p.m.
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2025-6541, CVE-2025-6542

Trust: 5.75

Fetched: Oct. 24, 2025, 9:29 a.m., Published: Oct. 5, 2025, midnight
Vulnerabilities: command injection, improper validation, path traversal
Affected productsExternal IDs
vendor: sauter model: case suite
db: NVD ids: CVE-2025-41722, CVE-2025-41720, CVE-2025-41723, CVE-2025-41724, CVE-2025-41721, CVE-2025-41719

Trust: 4.75

Fetched: Oct. 24, 2025, 9:27 a.m., Published: Sept. 26, 2025, 1:23 p.m.
Vulnerabilities: privilege escalation, code execution
Affected productsExternal IDs
vendor: cisco model: firepower
db: NVD ids: CVE-2025-20333, CVE-2025-20362

Trust: 4.25

Fetched: Oct. 24, 2025, 9:27 a.m., Published: Nov. 30, 0001, midnight
Vulnerabilities: certificate validation vulnerability
Affected productsExternal IDs
db: NVD ids: CVE-2022-38691

Trust: 4.5

Fetched: Oct. 24, 2025, 9:22 a.m., Published: -
Vulnerabilities: os command injection, command injection
Affected productsExternal IDs
vendor: brickcom model: brickcom
vendor: trend micro model: security
vendor: cisco model: linksys
vendor: cisco model: routers
vendor: trend model: security
vendor: four-faith model: four-faith
db: NVD ids: CVE-2024-3721, CVE-2024-12856

Trust: 3.0

Fetched: Oct. 24, 2025, 9:21 a.m., Published: Oct. 7, 2025, 8:25 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: cisco model: cisco adaptive security appliance
vendor: cisco model: adaptive security appliance

Trust: 4.25

Fetched: Oct. 24, 2025, 9:21 a.m., Published: Feb. 24, 2048, midnight
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2025-59287

Trust: 3.75

Fetched: Oct. 24, 2025, 9:21 a.m., Published: Oct. 23, 2025, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: snort model: snort
db: NVD ids: CVE-2025-9133