VYPR
Vendor

LOGITEC CORPORATION

Products
16
CVEs
17
Across products
31
Status
Private

Products

16

Recent CVEs

17
  • CVE-2023-35991CriAug 18, 2023
    risk 0.64cvss 9.8epss 0.01

    Hidden functionality vulnerability in LOGITEC wireless LAN routers allows an unauthenticated attacker to log in to the product's certain management console and execute arbitrary OS commands. Affected products and versions are as follows: LAN-W300N/DR all versions, LAN-WH300N/DR…

  • CVE-2023-32626CriAug 18, 2023
    risk 0.64cvss 9.8epss 0.01

    Hidden functionality vulnerability in LAN-W300N/RS all versions, and LAN-W300N/PR5 all versions allows an unauthenticated attacker to log in to the product's certain management console and execute arbitrary OS commands.

  • CVE-2023-37567CriJul 13, 2023
    risk 0.64cvss 9.8epss 0.02

    Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a remote unauthenticated attacker to execute an arbitrary command by sending a specially crafted request to a certain port of the web management page. Affected products and versions are as follows:…

  • CVE-2023-39445HigAug 18, 2023
    risk 0.57cvss 8.8epss 0.01

    Hidden functionality vulnerability in LAN-WH300N/RE all versions provided by LOGITEC CORPORATION allows an unauthenticated attacker to execute arbitrary code by sending a specially crafted file to the product's certain management console.

  • CVE-2023-38132HigAug 18, 2023
    risk 0.57cvss 8.8epss 0.00

    LAN-W451NGR all versions provided by LOGITEC CORPORATION contains an improper access control vulnerability, which allows an unauthenticated attacker to log in to telnet service.

  • CVE-2023-38576HigAug 18, 2023
    risk 0.52cvss 8.0epss 0.00

    Hidden functionality vulnerability in LAN-WH300N/RE all versions provided by LOGITEC CORPORATION allows an authenticated user to execute arbitrary OS commands on a certain management console.

  • CVE-2023-37566HigJul 13, 2023
    risk 0.52cvss 8.0epss 0.01

    Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a network-adjacent authenticated attacker to execute an arbitrary command by sending a specially crafted request to the web management page. Affected products and versions are as follows:…

  • CVE-2021-20640MedFeb 12, 2021
    risk 0.44cvss 6.8epss 0.01

    Buffer overflow vulnerability in LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute an arbitrary OS command via unspecified vectors.

  • CVE-2021-20639MedFeb 12, 2021
    risk 0.44cvss 6.8epss 0.00

    LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.

  • CVE-2021-20638MedFeb 12, 2021
    risk 0.44cvss 6.8epss 0.00

    LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.

  • CVE-2023-43757MedNov 16, 2023
    risk 0.42cvss 6.5epss 0.01

    Inadequate encryption strength vulnerability in multiple routers provided by ELECOM CO.,LTD. and LOGITEC CORPORATION allows a network-adjacent unauthenticated attacker to guess the encryption key used for wireless LAN communication and intercept the communication. As for the…

  • CVE-2021-20642MedFeb 12, 2021
    risk 0.42cvss 6.5epss 0.01

    Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/RS allows a remote attacker to cause a denial-of-service (DoS) condition by sending a specially crafted URL.

  • CVE-2021-20641MedFeb 12, 2021
    risk 0.42cvss 6.5epss 0.01

    Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/RS allows remote attackers to hijack the authentication of administrators via a specially crafted URL. As a result, unintended operations to the device such as changes of the device settings may be conducted.

  • CVE-2021-20637MedFeb 12, 2021
    risk 0.42cvss 6.5epss 0.01

    Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/PR5B allows a remote attacker to cause a denial-of-service (DoS) condition by sending a specially crafted URL.

  • CVE-2021-20636MedFeb 12, 2021
    risk 0.42cvss 6.5epss 0.01

    Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/PR5B allows remote attackers to hijack the authentication of administrators via a specially crafted URL. As a result, unintended operations to the device such as changes of the device settings may be conducted.

  • CVE-2021-20635MedFeb 12, 2021
    risk 0.42cvss 6.5epss 0.00

    Improper restriction of excessive authentication attempts in LOGITEC LAN-WH450N/GR allows an attacker in the wireless range of the device to recover PIN and access the network.

  • CVE-2012-1250Jun 4, 2012
    risk 0.00cvss epss 0.06

    Logitec LAN-W300N/R routers with firmware before 2.27 do not properly restrict login access, which allows remote attackers to obtain administrative privileges and modify settings via vectors related to PPPoE authentication.