Logitech
logitech
36 CVEs • 49 products
Products (49)
Click to collapseToggle
Products (49)
Click to collapse
CVEs (36)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options Plus version 1.60.496306 on macOS allows attackers to execute arbitrary code via insecure Electron Fuses configuration. |
Logitech Options+ on MacOS prior 1.72 allows a local attacker to inject dynamic library within Options+ runtime and abuse permissions granted by the user to Options+ such as Camera. |
Improper Control of Dynamically-Managed Code Resources vulnerability in Logitech Logi Tune on MacOS allows Local Code Inclusion. |
StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe. An attacker can execute arbitrary code via a crafted .exe file. |
An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves applications vulnerable to CSRF attacks during authentication and authorization operations. |
There is a Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability in Logitech Sync for Windows prior to 2.4.574. Successful exploitation of these vulnerabilities may escalate the permission to the system user. |
1Logitech 2S120 Firmware Z120 FirmwareNov 21, 2024 Aug 11, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Logitech Z120 and S120 speakers through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. The power indicator L...Show more |
1Logitech 1Lan W300n/rs Firmware Nov 21, 2024 Feb 12, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/RS allows a remote attacker to cause a denial-of-service (DoS) condition by sending a specially crafted URL. |
1Logitech 1Lan W300n/rs Firmware Nov 21, 2024 Feb 12, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/RS allows remote attackers to hijack the authentication of administrators via a specially crafted URL. As a result, unintended operations to the device...Show more |
1Logitech 1Lan W300n/pgrb Firmware Nov 21, 2024 Feb 12, 2021 N/A· v4 6.8 MEDIUM· v3 7.7 HIGH· v2 Buffer overflow vulnerability in LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute an arbitrary OS command via unspecified vectors. |
1Logitech 1Lan W300n/pgrb Firmware Nov 21, 2024 Feb 12, 2021 N/A· v4 6.8 MEDIUM· v3 7.7 HIGH· v2 LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors. |
1Logitech 1Lan W300n/pgrb Firmware Nov 21, 2024 Feb 12, 2021 N/A· v4 6.8 MEDIUM· v3 7.7 HIGH· v2 LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors. |
1Logitech 1Lan W300n/pr5b Firmware Nov 21, 2024 Feb 12, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/PR5B allows a remote attacker to cause a denial-of-service (DoS) condition by sending a specially crafted URL. |
1Logitech 1Lan W300n/pr5b Firmware Nov 21, 2024 Feb 12, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/PR5B allows remote attackers to hijack the authentication of administrators via a specially crafted URL. As a result, unintended operations to the devi...Show more |
1Logitech 1Lan Wh450n/gr Firmware Nov 21, 2024 Feb 12, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Improper restriction of excessive authentication attempts in LOGITEC LAN-WH450N/GR allows an attacker in the wireless range of the device to recover PIN and access the network. |
1Logitech 2K360 Firmware Unifying Receiver FirmwareNov 21, 2024 Jun 29, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Certain Logitech Unifying devices allow attackers to dump AES keys and addresses, leading to the capability of live decryption of Radio Frequency transmissions, as demonstrated by an attack against a Logitech K360 keyboa...Show more |
The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection. On Windows, any text may be injected by using ALT+NUMPAD input to bypass the restriction on the characters...Show more |
1Logitech 1Unifying Receiver Firmware Nov 21, 2024 Jun 29, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Logitech Unifying devices allow keystroke injection, bypassing encryption. The attacker must press a "magic" key combination while sniffing cryptographic data from a Radio Frequency transmission. NOTE: this issue exists...Show more |
1Logitech 1Unifying Receiver Firmware Nov 21, 2024 Jun 29, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Logitech Unifying devices allow live decryption if the pairing of a keyboard to a receiver is sniffed. |
1Logitech 5K360 Firmware K400r FirmwareK750 Firmware+2 moreNov 21, 2024 Jun 29, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack. |