VYPR

Vendor CVEs

Logitech

All CVEs

39 total · sorted by risk
  • CVE-2018-15723CriDec 20, 2018
    risk 0.64cvss 9.8epss 0.04

    The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request. An unauthenticated remote attacker can leverage this vulnerability to execute application defined commands (e.g. harmony.system?systeminfo).

  • CVE-2018-15721CriDec 20, 2018
    risk 0.64cvss 9.8epss 0.02

    The XMPP server in Logitech Harmony Hub before version 4.15.206 is vulnerable to authentication bypass via a crafted XMPP request. Remote attackers can use this vulnerability to gain access to the local API.

  • CVE-2018-15720CriDec 20, 2018
    risk 0.64cvss 9.8epss 0.01

    Logitech Harmony Hub before version 4.15.206 contained two hard-coded accounts in the XMPP server that gave remote users access to the local API.

  • CVE-2019-12506HigJun 7, 2019
    risk 0.57cvss 8.8epss 0.01

    Due to unencrypted and unauthenticated data communication, the wireless presenter Logitech R700 Laser Presentation Remote R-R0010 is prone to keystroke injection attacks. Thus, an attacker is able to send arbitrary keystrokes to a victim's computer system, e.g., to install…

  • CVE-2022-0916HigMay 3, 2022
    risk 0.55cvss 8.4epss 0.00

    An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves applications vulnerable to CSRF attacks during authentication and authorization operations.

  • CVE-2018-15722HigDec 20, 2018
    risk 0.53cvss 8.1epss 0.02

    The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request. A remote server or man in the middle can inject OS commands with a properly formatted response.

  • CVE-2024-8258HigSep 10, 2024
    risk 0.51cvss 7.8epss 0.00

    Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options Plus version 1.60.496306 on macOS allows attackers to execute arbitrary code via insecure Electron Fuses configuration.

  • CVE-2018-0621HigJul 26, 2018
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in LOGICOOL CONNECTION UTILITY SOFTWARE versions before 2.30.9 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2018-0620HigJul 26, 2018
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in LOGICOOL Game Software versions before 8.87.116 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2022-36263HigAug 19, 2022
    risk 0.47cvss 7.3epss 0.00

    StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe. An attacker can execute arbitrary code via a crafted .exe file.

  • CVE-2026-43049HigMay 1, 2026
    risk 0.44cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure Presently, if the force feedback initialisation fails when probing the Logitech G920 Driving Force Racing Wheel for Xbox…

  • CVE-2021-20640MedFeb 12, 2021
    risk 0.44cvss 6.8epss 0.01

    Buffer overflow vulnerability in LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute an arbitrary OS command via unspecified vectors.

  • CVE-2021-20639MedFeb 12, 2021
    risk 0.44cvss 6.8epss 0.00

    LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.

  • CVE-2021-20638MedFeb 12, 2021
    risk 0.44cvss 6.8epss 0.00

    LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.

  • CVE-2017-15687MedOct 23, 2017
    risk 0.43cvss 6.1epss 0.01

    DOM Based Cross Site Scripting (XSS) exists in Logitech Media Server 7.7.1, 7.7.2, 7.7.3, 7.7.5, 7.7.6, 7.9.0, and 7.9.1 via a crafted URI.

  • CVE-2021-20642MedFeb 12, 2021
    risk 0.42cvss 6.5epss 0.01

    Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/RS allows a remote attacker to cause a denial-of-service (DoS) condition by sending a specially crafted URL.

  • CVE-2021-20641MedFeb 12, 2021
    risk 0.42cvss 6.5epss 0.01

    Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/RS allows remote attackers to hijack the authentication of administrators via a specially crafted URL. As a result, unintended operations to the device such as changes of the device settings may be conducted.

  • CVE-2021-20637MedFeb 12, 2021
    risk 0.42cvss 6.5epss 0.01

    Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/PR5B allows a remote attacker to cause a denial-of-service (DoS) condition by sending a specially crafted URL.

  • CVE-2021-20636MedFeb 12, 2021
    risk 0.42cvss 6.5epss 0.01

    Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/PR5B allows remote attackers to hijack the authentication of administrators via a specially crafted URL. As a result, unintended operations to the device such as changes of the device settings may be conducted.

  • CVE-2021-20635MedFeb 12, 2021
    risk 0.42cvss 6.5epss 0.00

    Improper restriction of excessive authentication attempts in LOGITEC LAN-WH450N/GR allows an attacker in the wireless range of the device to recover PIN and access the network.

  • CVE-2019-13055MedJun 29, 2019
    risk 0.42cvss 6.5epss 0.01

    Certain Logitech Unifying devices allow attackers to dump AES keys and addresses, leading to the capability of live decryption of Radio Frequency transmissions, as demonstrated by an attack against a Logitech K360 keyboard.

  • CVE-2019-13054MedJun 29, 2019
    risk 0.42cvss 6.5epss 0.01

    The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection. On Windows, any text may be injected by using ALT+NUMPAD input to bypass the restriction on the characters A through Z.

  • CVE-2019-13053MedJun 29, 2019
    risk 0.42cvss 6.5epss 0.01

    Logitech Unifying devices allow keystroke injection, bypassing encryption. The attacker must press a "magic" key combination while sniffing cryptographic data from a Radio Frequency transmission. NOTE: this issue exists because of an incomplete fix for CVE-2016-10761.

  • CVE-2019-13052MedJun 29, 2019
    risk 0.42cvss 6.5epss 0.01

    Logitech Unifying devices allow live decryption if the pairing of a keyboard to a receiver is sniffed.

  • CVE-2016-10761MedJun 29, 2019
    risk 0.42cvss 6.5epss 0.01

    Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.

  • CVE-2016-6257MedAug 2, 2016
    risk 0.42cvss 6.5epss 0.01

    The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM600 and Ultraslim Wireless mice, does not enforce incrementing AES counters, which allows remote attackers to inject encrypted keyboard input…

  • CVE-2022-0915MedApr 12, 2022
    risk 0.39cvss 6.0epss 0.00

    There is a Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability in Logitech Sync for Windows prior to 2.4.574. Successful exploitation of these vulnerabilities may escalate the permission to the system user.

  • CVE-2021-38547MedAug 11, 2021
    risk 0.38cvss 5.9epss 0.01

    Logitech Z120 and S120 speakers through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. The power indicator LED of the speakers is connected directly to the power line,…

  • CVE-2017-16568MedNov 10, 2017
    risk 0.38cvss 5.4epss 0.02

    Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Radio" functionality. This vulnerability allows attackers to inject malicious JavaScript payloads, which become permanently stored on the server and execute when a user plays the…

  • CVE-2017-16567MedNov 10, 2017
    risk 0.38cvss 5.4epss 0.02

    Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Favorites" feature. This vulnerability allows remote attackers to inject and permanently store malicious JavaScript payloads, which are executed when users access the affected…

  • CVE-2024-8011MedAug 25, 2024
    risk 0.36cvss 5.5epss 0.00

    Logitech Options+ on MacOS prior 1.72 allows a local attacker to inject dynamic library within Options+ runtime and abuse permissions granted by the user to Options+ such as Camera.

  • CVE-2024-4031MedApr 23, 2024
    risk 0.29cvss 4.4epss 0.00

    Unquoted Search Path or Element vulnerability in Logitech MEVO WEBCAM APP on Windows allows Local Execution of Code.

  • CVE-2024-2537MedMar 15, 2024
    risk 0.29cvss 4.4epss 0.00

    Improper Control of Dynamically-Managed Code Resources vulnerability in Logitech Logi Tune on MacOS allows Local Code Inclusion.

  • CVE-2007-2918Jun 1, 2007
    risk 0.06cvss epss 0.34

    Multiple stack-based buffer overflows in ActiveX controls (1) VibeC in (a) vibecontrol.dll, (2) CallManager and (3) ViewerClient in (b) StarClient.dll, (4) ComLink in (c) uicomlink.dll, and (5) WebCamXMP in (d) wcamxmp.dll in Logitech VideoCall allow remote attackers to cause a…

  • CVE-2008-0956Jun 12, 2008
    risk 0.01cvss epss 0.08

    Multiple stack-based buffer overflows in the BackWeb Lite Install Runner ActiveX control in the BackWeb Web Package ActiveX object in LiteInstActivator.dll in BackWeb before 8.1.1.87, as used in Logitech Desktop Manager (LDM) before 2.56, allow remote attackers to execute…

  • CVE-2022-46338MedNov 30, 2022
    risk 0.00cvss 6.5epss 0.01

    g810-led 0.4.2, a LED configuration tool for Logitech Gx10 keyboards, contained a udev rule to make supported device nodes world-readable and writable, allowing any process on the system to read traffic from keyboards, including sensitive data.

  • CVE-2012-1250Jun 4, 2012
    risk 0.00cvss epss 0.06

    Logitec LAN-W300N/R routers with firmware before 2.27 do not properly restrict login access, which allows remote attackers to obtain administrative privileges and modify settings via vectors related to PPPoE authentication.

  • CVE-2002-1722Dec 31, 2002
    risk 0.00cvss epss 0.00

    Logitech iTouch keyboards allows attackers with physical access to the system to bypass the screen locking function and execute user-defined commands that have been assigned to a button.

  • CVE-2001-0737Oct 18, 2001
    risk 0.00cvss epss 0.02

    A long 'synch' delay in Logitech wireless mice and keyboard receivers allows a remote attacker to hijack connections via a man-in-the-middle attack.