VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202606-1203 CVE-2026-20262 Cisco Systems Cisco Catalyst SD-WAN Manager Past traversal vulnerability in CVSS V2: -
CVSS V3: 6.5
Severity: MEDIUM
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate user-supplied input during a file upload process. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system. A successful exploit could allow the attacker to create or overwrite any file on the underlying operating system. This file could later be used to elevate to root. To exploit this vulnerability, the attacker must have valid credentials with at least a lower-privileged, single-task user account. An attacker could use a specially crafted... root This vulnerability can be used to escalate privileges. • All information handled by this software may be overwritten. • This software will not stop
VAR-202606-0848 CVE-2026-12174 D-Link Corporation of DCS-935L  Multiple vulnerabilities in firmware CVSS V2: 9.0
CVSS V3: 8.8
Severity: High
A security vulnerability has been detected in D-Link DCS-935L 1.10.01. This issue affects the function snprintf of the file /web/cgi-bin/greece/rhea of the component HTTP Handler. Such manipulation of the argument data leads to format string. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The exploit is publicly available and could be misused.- All information handled by the software may be leaked to external parties. - All information handled by the software may be overwritten. - The software may completely shut down
VAR-202606-2782 CVE-2026-9213 CVSS V2: -
CVSS V3: 8.1
Severity: HIGH
A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execute code on the device.
VAR-202606-1905 CVE-2026-9212 CVSS V2: -
CVSS V3: 8.0
Severity: HIGH
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.
VAR-202606-2783 CVE-2026-9210 CVSS V2: -
CVSS V3: 4.5
Severity: MEDIUM
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
VAR-202606-2971 CVE-2026-0420 CVSS V2: -
CVSS V3: 5.9
Severity: MEDIUM
An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting the product's confidentiality. This vulnerability affects the listed NETGEAR models.
VAR-202606-3571 CVE-2026-0419 CVSS V2: -
CVSS V3: 8.0
Severity: HIGH
Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows users connected to the local WiFi Networks to execute operating system commands. NETGEAR JR6150 has reached End-of-Support phase as of 2018 , and no further security updates are planned. NETGEAR strongly recommends replacing these devices with newer NETGEAR models to ensure continued security support and updates. This vulnerability has been identified through firmware emulation in a controlled research environment and has not been verified on production hardware.
VAR-202606-2103 CVE-2026-0415 CVSS V2: -
CVSS V3: 4.5
Severity: MEDIUM
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
VAR-202606-3181 CVE-2026-0413 CVSS V2: -
CVSS V3: 4.5
Severity: MEDIUM
A buffer overflow vulnerability due to insufficient input validation in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
VAR-202606-2972 CVE-2026-0410 CVSS V2: -
CVSS V3: 4.5
Severity: MEDIUM
Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router software and functionality.
VAR-202606-1595 CVE-2026-25089 fortinet's FortiSandbox In multiple products such as OS  Command injection vulnerability CVSS V2: -
CVSS V3: 9.8
Severity: CRITICAL
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. This vulnerability allows an unauthenticated attacker to use a specially crafted attacker. HTTP It may be possible to execute malicious commands through the request.- All information handled by the software may be leaked to external parties. - All information handled by the software may be overwritten. - The software may completely shut down
VAR-202606-0053 CVE-2026-46749 Siemens' SINEC INS predictable in  Salt  One-Way Hash Usage Vulnerability CVSS V2: -
CVSS V3: 7.5
Severity: Medium
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implementation with a static, hardcoded salt shared across all users and installations, and is configured with an insufficient number of iterations. This could allow an attacker to efficiently recover user passwords using brute-force or precomputed attacks, potentially resulting in unauthorized access. - All information handled by the software may be overwritten. - The software may completely shut down
VAR-202606-0051 CVE-2026-46748 Siemens' SINEC INS Unnecessary Privileged Execution Vulnerability in CVSS V2: -
CVSS V3: 8.8
Severity: High
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected system includes a binary that is configured with the cap_dac_override capability. This capability allows the process to bypass file system permission checks, resulting in unrestricted file system access. This could allow a local attacker to escalate privileges leading to arbitrary file modification and gaining root privileges on the system. root It is possible to obtain the necessary permissions.- All information handled by the software may be leaked to external parties. - All information handled by the software may be overwritten. - The software may completely shut down
VAR-202606-0054 CVE-2026-46747 Siemens' SINEC INS Past traversal vulnerability in CVSS V2: -
CVSS V3: 4.3
Severity: Medium
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application does not properly sanitize path input in the `GET /api/sftp/uploadFiles` endpoint used for directory listing. This allows path traversal through crafted input, enabling access to unintended file system locations. - No rewriting will occur to the information handled by the software. - The software will not stop
VAR-202606-0052 CVE-2026-46746 Siemens' SINEC INS In OS  Command injection vulnerability CVSS V2: -
CVSS V3: 8.8
Severity: High
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The application does not properly sanitize user input in the /api/sftp/uploadFiles endpoint, allowing the injection of shell command payloads via crafted directory names. These payloads are stored and executed when directory listings are retrieved. This could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system with the privileges of the affected service user (sinecins). - All information handled by the software may be overwritten. - The software may completely shut down
VAR-202606-0933 CVE-2026-11492 D-Link Corporation of DIR-823G  Multiple vulnerabilities in firmware CVSS V2: 4.0
CVSS V3: 4.3
Severity: Low
A security flaw has been discovered in D-Link DIR-823G 1.0.2B05. The affected element is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Performing a manipulation results in least privilege violation. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. Techniques exploiting this vulnerability have been publicly disclosed and could be used in attacks.- All information handled by the software may be leaked to external parties. - All information handled by the software may be overwritten. - The software may completely shut down
VAR-202606-1108 CVE-2026-20245 Cisco Systems Cisco Catalyst SD-WAN Manager Vulnerabilities related to encoding and escaping in multiple products such as the above. CVSS V2: -
CVSS V3: 7.8
Severity: HIGH
A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to perform command injection attacks on an affected system and elevate their privileges as the root user.&nbsp; To exploit this vulnerability, the attacker must have netadmin privileges on the affected system. This would require valid credentials or exploitation of or . Cisco is not aware of successful exploitation by other methods. Cisco has observed limited cases where the exploitation of this bug resulted in a configuration change pushed to edge devices. Cisco recommends that customers upgrade to the fixed software that is documented in the that was published on May 14, 2026, and verify the configuration of the edge devices. root It may be possible to execute arbitrary commands with the appropriate privileges. root It is possible to elevate privileges as a user. - All information handled by the software may be overwritten. - The software may completely shut down
VAR-202606-1867 CVE-2026-1871 TP-LINK Technologies of tapo c200  Stack-based buffer overflow vulnerability in firmware CVSS V2: -
CVSS V3: 6.5
Severity: MEDIUM
TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header field lengths, which can be triggered by a crafted authentication request. Successful exploitation causes the affected RTSP core service process to crash and triggers an automatic system reboot, resulting in a denial of service (DoS) condition. This prevents legitimate users from accessing the camera’s live video stream or management interface until the service restarts. If this vulnerability is exploited, affected systems will be affected. - No information handled by the software will be rewritten. - The software may completely shut down
VAR-202606-1002 CVE-2026-35718 VIVOTEK Inc. of Network Camera FD8136  Path traversal vulnerability in firmware CVSS V2: -
CVSS V3: 6.5
Severity: MEDIUM
A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmware 0300a allows authenticated attackers to read any file on the device via sending a crafted request. - No rewriting will occur to the information handled by the software. - The software will not stop
VAR-202606-1526 CVE-2026-35716 VIVOTEK Inc. of Network Camera FD8136  Stack-based buffer overflow vulnerability in firmware CVSS V2: -
CVSS V3: 6.3
Severity: MEDIUM
A stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via an oversized n1 parameter in a POST request to the /cgi-bin/admin/setpm.cgi, /cgi-bin/admin/setmd.cgi, or /cgi-bin/admin/setmd_profile.cgi endpoint (all symlinks to the same binary). The parameter value is copied into a fixed-size 0xa4-byte stack buffer without bounds checking, overwriting the saved link register. The binary is compiled without stack canaries. The value of this parameter is fixed in size. - Some of the information handled by the software may be overwritten. - Some parts of the software may stop working