VYPR
Vendor

Logitech

Products
49
CVEs
39
Across products
54
Status
Private

Products

49
View all 49 products →

Recent CVEs

39
View all 39 CVEs →
  • CVE-2018-15723CriDec 20, 2018
    risk 0.64cvss 9.8epss 0.04

    The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request. An unauthenticated remote attacker can leverage this vulnerability to execute application defined commands (e.g. harmony.system?systeminfo).

  • CVE-2018-15721CriDec 20, 2018
    risk 0.64cvss 9.8epss 0.02

    The XMPP server in Logitech Harmony Hub before version 4.15.206 is vulnerable to authentication bypass via a crafted XMPP request. Remote attackers can use this vulnerability to gain access to the local API.

  • CVE-2018-15720CriDec 20, 2018
    risk 0.64cvss 9.8epss 0.01

    Logitech Harmony Hub before version 4.15.206 contained two hard-coded accounts in the XMPP server that gave remote users access to the local API.

  • CVE-2019-12506HigJun 7, 2019
    risk 0.57cvss 8.8epss 0.01

    Due to unencrypted and unauthenticated data communication, the wireless presenter Logitech R700 Laser Presentation Remote R-R0010 is prone to keystroke injection attacks. Thus, an attacker is able to send arbitrary keystrokes to a victim's computer system, e.g., to install…

  • CVE-2022-0916HigMay 3, 2022
    risk 0.55cvss 8.4epss 0.00

    An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves applications vulnerable to CSRF attacks during authentication and authorization operations.

  • CVE-2018-15722HigDec 20, 2018
    risk 0.53cvss 8.1epss 0.02

    The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request. A remote server or man in the middle can inject OS commands with a properly formatted response.

  • CVE-2024-8258HigSep 10, 2024
    risk 0.51cvss 7.8epss 0.00

    Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options Plus version 1.60.496306 on macOS allows attackers to execute arbitrary code via insecure Electron Fuses configuration.

  • CVE-2018-0621HigJul 26, 2018
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in LOGICOOL CONNECTION UTILITY SOFTWARE versions before 2.30.9 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2018-0620HigJul 26, 2018
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in LOGICOOL Game Software versions before 8.87.116 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2022-36263HigAug 19, 2022
    risk 0.47cvss 7.3epss 0.00

    StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe. An attacker can execute arbitrary code via a crafted .exe file.

  • CVE-2026-43049HigMay 1, 2026
    risk 0.44cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure Presently, if the force feedback initialisation fails when probing the Logitech G920 Driving Force Racing Wheel for Xbox…

  • CVE-2021-20640MedFeb 12, 2021
    risk 0.44cvss 6.8epss 0.01

    Buffer overflow vulnerability in LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute an arbitrary OS command via unspecified vectors.

  • CVE-2021-20639MedFeb 12, 2021
    risk 0.44cvss 6.8epss 0.00

    LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.

  • CVE-2021-20638MedFeb 12, 2021
    risk 0.44cvss 6.8epss 0.00

    LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.

  • CVE-2017-15687MedOct 23, 2017
    risk 0.43cvss 6.1epss 0.01

    DOM Based Cross Site Scripting (XSS) exists in Logitech Media Server 7.7.1, 7.7.2, 7.7.3, 7.7.5, 7.7.6, 7.9.0, and 7.9.1 via a crafted URI.

  • CVE-2021-20642MedFeb 12, 2021
    risk 0.42cvss 6.5epss 0.01

    Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/RS allows a remote attacker to cause a denial-of-service (DoS) condition by sending a specially crafted URL.

  • CVE-2021-20641MedFeb 12, 2021
    risk 0.42cvss 6.5epss 0.01

    Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/RS allows remote attackers to hijack the authentication of administrators via a specially crafted URL. As a result, unintended operations to the device such as changes of the device settings may be conducted.

  • CVE-2021-20637MedFeb 12, 2021
    risk 0.42cvss 6.5epss 0.01

    Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/PR5B allows a remote attacker to cause a denial-of-service (DoS) condition by sending a specially crafted URL.

  • CVE-2021-20636MedFeb 12, 2021
    risk 0.42cvss 6.5epss 0.01

    Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/PR5B allows remote attackers to hijack the authentication of administrators via a specially crafted URL. As a result, unintended operations to the device such as changes of the device settings may be conducted.

  • CVE-2021-20635MedFeb 12, 2021
    risk 0.42cvss 6.5epss 0.00

    Improper restriction of excessive authentication attempts in LOGITEC LAN-WH450N/GR allows an attacker in the wireless range of the device to recover PIN and access the network.