Skip to content
Noroxi

Logitech records

37 published records for vendor logitech.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

37 records
  • Logitec LAN-W300N/R routers with firmware before 2.27 do not properly restrict login access, which allows remote attackers to obtain adminis

    CriticalCVSS 10.0No exploitEPSS 6%

    logitech · lan-w300n\/ru2 firmwareJun 4, 2012

  • Multiple stack-based buffer overflows in the BackWeb Lite Install Runner ActiveX control in the BackWeb Web Package ActiveX object in LiteIn

    CriticalCVSS 9.3No exploitEPSS 8%

    backweb · backwebJun 11, 2008

  • The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request.

    CriticalCVSS 9.8No exploitEPSS 4%

    logitech · harmony hub firmwareDec 20, 2018

  • The XMPP server in Logitech Harmony Hub before version 4.15.206 is vulnerable to authentication bypass via a crafted XMPP request.

    CriticalCVSS 9.8No exploitEPSS 2%

    logitech · harmony hub firmwareDec 20, 2018

  • Logitech Harmony Hub before version 4.15.206 contained two hard-coded accounts in the XMPP server that gave remote users access to the local

    CriticalCVSS 9.8No exploitEPSS 1%

    logitech · harmony hub firmwareDec 20, 2018

  • CVE-2024-2537
    39Monitor

    Electron Code Injection in Logi Tune macOS Application

    CriticalCVSS 9.8No exploitEPSS 0%

    logitech · logi tuneMar 15, 2024

  • CVE-2007-2918
    37Monitor

    Multiple stack-based buffer overflows in ActiveX controls (1) VibeC in (a) vibecontrol.dll, (2) CallManager and (3) ViewerClient in (b) Star

    MediumCVSS 6.8WeaponizedEPSS 34%

    logitech · videocallMay 31, 2007

  • Due to unencrypted and unauthenticated data communication, the wireless presenter Logitech R700 Laser Presentation Remote R-R0010 is prone t

    HighCVSS 8.8No exploitEPSS 1%

    logitech · r700 laser presentation remote firmwareJun 7, 2019

  • CVE-2022-0916
    35Monitor

    Broken authentication on Logitech Options due to misvalidation of Oauth state parameter

    HighCVSS 8.8No exploitEPSS 0%

    logitech · optionsMay 3, 2022

  • The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request.

    HighCVSS 8.1No exploitEPSS 2%

    logitech · harmony hub firmwareDec 20, 2018

  • CVE-2001-0737
    31Monitor

    A long 'synch' delay in Logitech wireless mice and keyboard receivers allows a remote attacker to hijack connections via a man-in-the-middle

    HighCVSS 7.5No exploitEPSS 2%

    logitech · cordless freedomOct 18, 2001

  • CVE-2018-0620
    31Monitor

    Untrusted search path vulnerability in LOGICOOL Game Software versions before 8.87.116 allows an attacker to gain privileges via a Trojan ho

    HighCVSS 7.8No exploitEPSS 1%

    logitech · game softwareJul 26, 2018

  • CVE-2018-0621
    31Monitor

    Untrusted search path vulnerability in LOGICOOL CONNECTION UTILITY SOFTWARE versions before 2.30.9 allows an attacker to gain privileges via

    HighCVSS 7.8No exploitEPSS 1%

    logitech · connection utility softwareJul 26, 2018

  • StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe.

    HighCVSS 7.3No exploitEPSS 0%

    logitech · streamlabs desktopAug 19, 2022

  • CVE-2022-0915
    28Monitor

    Logitech Sync desktop application prior to 2.4.574 - TOCTOU during installation leads to privelege escalation

    HighCVSS 7.0No exploitEPSS 0%

    logitech · syncApr 12, 2022

  • Buffer overflow vulnerability in LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute an arbitrary OS command

    MediumCVSS 6.8No exploitEPSS 1%

    logitech · lan-w300n\/pgrb firmwareFeb 12, 2021

  • LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.

    MediumCVSS 6.8No exploitEPSS 0%

    logitech · lan-w300n\/pgrb firmwareFeb 12, 2021

  • LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.

    MediumCVSS 6.8No exploitEPSS 0%

    logitech · lan-w300n\/pgrb firmwareFeb 12, 2021

  • Certain Logitech Unifying devices allow attackers to dump AES keys and addresses, leading to the capability of live decryption of Radio Freq

    MediumCVSS 6.5No exploitEPSS 1%

    logitech · unifying receiver firmwareJun 29, 2019

  • Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/RS allows a remote attacker to cause a denial-of-service (DoS) con

    MediumCVSS 6.5No exploitEPSS 1%

    logitech · lan-w300n\/rs firmwareFeb 12, 2021

  • Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/PR5B allows a remote attacker to cause a denial-of-service (DoS) c

    MediumCVSS 6.5No exploitEPSS 1%

    logitech · lan-w300n\/pr5b firmwareFeb 12, 2021

  • CVE-2016-6257
    26Monitor

    The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM60

    MediumCVSS 6.5No exploitEPSS 1%

    lenovo · ultraslim firmwareAug 2, 2016

  • The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection.

    MediumCVSS 6.5No exploitEPSS 1%

    logitech · r500 firmwareJun 29, 2019

  • Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.

    MediumCVSS 6.5No exploitEPSS 1%

    logitech · k400r firmwareJun 29, 2019

  • Logitech Unifying devices allow live decryption if the pairing of a keyboard to a receiver is sniffed.

    MediumCVSS 6.5No exploitEPSS 1%

    logitech · unifying receiver firmwareJun 29, 2019