Logitech records
37 published records for vendor logitech.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 2.7%
- Pre-auth RCE
- 5
- With a fix record
- 2.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-287 Improper Authentication2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-426 Untrusted Search Path2
- CWE-306 Missing Authentication for Critical Function1
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
37 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2012-1250No exploit | Logitec LAN-W300N/R routers with firmware before 2.27 do not properly restrict login access, which allows remote attackers to obtain adminislogitech · lan-w300n\/ru2 firmware · CWE-264 | Critical10.0 | — | 5.9% | Jun 4, 2012 |
40Plan | CVE-2008-0956No exploit | Multiple stack-based buffer overflows in the BackWeb Lite Install Runner ActiveX control in the BackWeb Web Package ActiveX object in LiteInbackweb · backweb · CWE-119 | Critical9.3 | — | 8.4% | Jun 11, 2008 |
40Plan | CVE-2018-15723No exploit | The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request.logitech · harmony hub firmware · CWE-346 | Critical9.8 | — | 3.7% | Dec 20, 2018 |
40Plan | CVE-2018-15721No exploit | The XMPP server in Logitech Harmony Hub before version 4.15.206 is vulnerable to authentication bypass via a crafted XMPP request.logitech · harmony hub firmware · CWE-287 | Critical9.8 | — | 1.8% | Dec 20, 2018 |
39Monitor | CVE-2018-15720No exploit | Logitech Harmony Hub before version 4.15.206 contained two hard-coded accounts in the XMPP server that gave remote users access to the locallogitech · harmony hub firmware · CWE-798 | Critical9.8 | — | 1.5% | Dec 20, 2018 |
39Monitor | CVE-2024-2537No exploit | Electron Code Injection in Logi Tune macOS Applicationlogitech · logi tune · CWE-913 | Critical9.8 | — | 0.3% | Mar 15, 2024 |
37Monitor | CVE-2007-2918Weaponized | Multiple stack-based buffer overflows in ActiveX controls (1) VibeC in (a) vibecontrol.dll, (2) CallManager and (3) ViewerClient in (b) Starlogitech · videocall | Medium6.8 | — | 34.1% | May 31, 2007 |
35Monitor | CVE-2019-12506No exploit | Due to unencrypted and unauthenticated data communication, the wireless presenter Logitech R700 Laser Presentation Remote R-R0010 is prone tlogitech · r700 laser presentation remote firmware · CWE-306 | High8.8 | — | 1.3% | Jun 7, 2019 |
35Monitor | CVE-2022-0916No exploit | Broken authentication on Logitech Options due to misvalidation of Oauth state parameterlogitech · options · CWE-287 | High8.8 | — | 0.5% | May 3, 2022 |
32Monitor | CVE-2018-15722No exploit | The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request.logitech · harmony hub firmware · CWE-78 | High8.1 | — | 1.6% | Dec 20, 2018 |
31Monitor | CVE-2001-0737No exploit | A long 'synch' delay in Logitech wireless mice and keyboard receivers allows a remote attacker to hijack connections via a man-in-the-middlelogitech · cordless freedom | High7.5 | — | 1.7% | Oct 18, 2001 |
31Monitor | CVE-2018-0620No exploit | Untrusted search path vulnerability in LOGICOOL Game Software versions before 8.87.116 allows an attacker to gain privileges via a Trojan hologitech · game software · CWE-426 | High7.8 | — | 0.9% | Jul 26, 2018 |
31Monitor | CVE-2018-0621No exploit | Untrusted search path vulnerability in LOGICOOL CONNECTION UTILITY SOFTWARE versions before 2.30.9 allows an attacker to gain privileges vialogitech · connection utility software · CWE-426 | High7.8 | — | 0.9% | Jul 26, 2018 |
29Monitor | CVE-2022-36263No exploit | StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe.logitech · streamlabs desktop · CWE-284 | High7.3 | — | 0.4% | Aug 19, 2022 |
28Monitor | CVE-2022-0915No exploit | Logitech Sync desktop application prior to 2.4.574 - TOCTOU during installation leads to privelege escalationlogitech · sync · CWE-367 | High7.0 | — | 0.2% | Apr 12, 2022 |
27Monitor | CVE-2021-20640No exploit | Buffer overflow vulnerability in LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute an arbitrary OS command logitech · lan-w300n\/pgrb firmware · CWE-120 | Medium6.8 | — | 0.6% | Feb 12, 2021 |
27Monitor | CVE-2021-20638No exploit | LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.logitech · lan-w300n\/pgrb firmware · CWE-78 | Medium6.8 | — | 0.5% | Feb 12, 2021 |
27Monitor | CVE-2021-20639No exploit | LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.logitech · lan-w300n\/pgrb firmware · CWE-78 | Medium6.8 | — | 0.5% | Feb 12, 2021 |
26Monitor | CVE-2019-13055No exploit | Certain Logitech Unifying devices allow attackers to dump AES keys and addresses, leading to the capability of live decryption of Radio Freqlogitech · unifying receiver firmware · CWE-200 | Medium6.5 | — | 1.0% | Jun 29, 2019 |
26Monitor | CVE-2021-20642No exploit | Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/RS allows a remote attacker to cause a denial-of-service (DoS) conlogitech · lan-w300n\/rs firmware | Medium6.5 | — | 1.0% | Feb 12, 2021 |
26Monitor | CVE-2021-20637No exploit | Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/PR5B allows a remote attacker to cause a denial-of-service (DoS) clogitech · lan-w300n\/pr5b firmware | Medium6.5 | — | 1.0% | Feb 12, 2021 |
26Monitor | CVE-2016-6257No exploit | The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM60lenovo · ultraslim firmware · CWE-310 | Medium6.5 | — | 1.0% | Aug 2, 2016 |
26Monitor | CVE-2019-13054No exploit | The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection.logitech · r500 firmware · CWE-522 | Medium6.5 | — | 0.8% | Jun 29, 2019 |
26Monitor | CVE-2016-10761No exploit | Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.logitech · k400r firmware · CWE-74 | Medium6.5 | — | 0.7% | Jun 29, 2019 |
26Monitor | CVE-2019-13052No exploit | Logitech Unifying devices allow live decryption if the pairing of a keyboard to a receiver is sniffed.logitech · unifying receiver firmware · CWE-327 | Medium6.5 | — | 0.7% | Jun 29, 2019 |
- CVE-2012-125042Plan
Logitec LAN-W300N/R routers with firmware before 2.27 do not properly restrict login access, which allows remote attackers to obtain adminis
CriticalCVSS 10.0No exploitEPSS 6%logitech · lan-w300n\/ru2 firmwareJun 4, 2012
- CVE-2008-095640Plan
Multiple stack-based buffer overflows in the BackWeb Lite Install Runner ActiveX control in the BackWeb Web Package ActiveX object in LiteIn
CriticalCVSS 9.3No exploitEPSS 8%backweb · backwebJun 11, 2008
- CVE-2018-1572340Plan
The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request.
CriticalCVSS 9.8No exploitEPSS 4%logitech · harmony hub firmwareDec 20, 2018
- CVE-2018-1572140Plan
The XMPP server in Logitech Harmony Hub before version 4.15.206 is vulnerable to authentication bypass via a crafted XMPP request.
CriticalCVSS 9.8No exploitEPSS 2%logitech · harmony hub firmwareDec 20, 2018
- CVE-2018-1572039Monitor
Logitech Harmony Hub before version 4.15.206 contained two hard-coded accounts in the XMPP server that gave remote users access to the local
CriticalCVSS 9.8No exploitEPSS 1%logitech · harmony hub firmwareDec 20, 2018
- CVE-2024-253739Monitor
Electron Code Injection in Logi Tune macOS Application
CriticalCVSS 9.8No exploitEPSS 0%logitech · logi tuneMar 15, 2024
- CVE-2007-291837Monitor
Multiple stack-based buffer overflows in ActiveX controls (1) VibeC in (a) vibecontrol.dll, (2) CallManager and (3) ViewerClient in (b) Star
MediumCVSS 6.8WeaponizedEPSS 34%logitech · videocallMay 31, 2007
- CVE-2019-1250635Monitor
Due to unencrypted and unauthenticated data communication, the wireless presenter Logitech R700 Laser Presentation Remote R-R0010 is prone t
HighCVSS 8.8No exploitEPSS 1%logitech · r700 laser presentation remote firmwareJun 7, 2019
- CVE-2022-091635Monitor
Broken authentication on Logitech Options due to misvalidation of Oauth state parameter
HighCVSS 8.8No exploitEPSS 0%logitech · optionsMay 3, 2022
- CVE-2018-1572232Monitor
The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request.
HighCVSS 8.1No exploitEPSS 2%logitech · harmony hub firmwareDec 20, 2018
- CVE-2001-073731Monitor
A long 'synch' delay in Logitech wireless mice and keyboard receivers allows a remote attacker to hijack connections via a man-in-the-middle
HighCVSS 7.5No exploitEPSS 2%logitech · cordless freedomOct 18, 2001
- CVE-2018-062031Monitor
Untrusted search path vulnerability in LOGICOOL Game Software versions before 8.87.116 allows an attacker to gain privileges via a Trojan ho
HighCVSS 7.8No exploitEPSS 1%logitech · game softwareJul 26, 2018
- CVE-2018-062131Monitor
Untrusted search path vulnerability in LOGICOOL CONNECTION UTILITY SOFTWARE versions before 2.30.9 allows an attacker to gain privileges via
HighCVSS 7.8No exploitEPSS 1%logitech · connection utility softwareJul 26, 2018
- CVE-2022-3626329Monitor
StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe.
HighCVSS 7.3No exploitEPSS 0%logitech · streamlabs desktopAug 19, 2022
- CVE-2022-091528Monitor
Logitech Sync desktop application prior to 2.4.574 - TOCTOU during installation leads to privelege escalation
HighCVSS 7.0No exploitEPSS 0%logitech · syncApr 12, 2022
- CVE-2021-2064027Monitor
Buffer overflow vulnerability in LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute an arbitrary OS command
MediumCVSS 6.8No exploitEPSS 1%logitech · lan-w300n\/pgrb firmwareFeb 12, 2021
- CVE-2021-2063827Monitor
LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.
MediumCVSS 6.8No exploitEPSS 0%logitech · lan-w300n\/pgrb firmwareFeb 12, 2021
- CVE-2021-2063927Monitor
LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.
MediumCVSS 6.8No exploitEPSS 0%logitech · lan-w300n\/pgrb firmwareFeb 12, 2021
- CVE-2019-1305526Monitor
Certain Logitech Unifying devices allow attackers to dump AES keys and addresses, leading to the capability of live decryption of Radio Freq
MediumCVSS 6.5No exploitEPSS 1%logitech · unifying receiver firmwareJun 29, 2019
- CVE-2021-2064226Monitor
Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/RS allows a remote attacker to cause a denial-of-service (DoS) con
MediumCVSS 6.5No exploitEPSS 1%logitech · lan-w300n\/rs firmwareFeb 12, 2021
- CVE-2021-2063726Monitor
Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/PR5B allows a remote attacker to cause a denial-of-service (DoS) c
MediumCVSS 6.5No exploitEPSS 1%logitech · lan-w300n\/pr5b firmwareFeb 12, 2021
- CVE-2016-625726Monitor
The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM60
MediumCVSS 6.5No exploitEPSS 1%lenovo · ultraslim firmwareAug 2, 2016
- CVE-2019-1305426Monitor
The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection.
MediumCVSS 6.5No exploitEPSS 1%logitech · r500 firmwareJun 29, 2019
- CVE-2016-1076126Monitor
Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.
MediumCVSS 6.5No exploitEPSS 1%logitech · k400r firmwareJun 29, 2019
- CVE-2019-1305226Monitor
Logitech Unifying devices allow live decryption if the pairing of a keyboard to a receiver is sniffed.
MediumCVSS 6.5No exploitEPSS 1%logitech · unifying receiver firmwareJun 29, 2019