Westermo
westermo
20 CVEs • 25 products
Products (25)
Click to collapseToggle
Products (25)
Click to collapse
CVEs (20)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Westermo 1L210 F2g Lynx Firmware Jul 30, 2025 Jun 20, 2024 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 An attacker may be able to cause a denial-of-service condition by sending many packets repeatedly. |
An attacker may be able to cause a denial-of-service condition by sending many SSH packets repeatedly. |
Plain text credentials and session ID can be captured with a network sniffer. |
A potential attacker with access to the Westermo Lynx device may be able to execute malicious code that could affect the correct functioning of the device.
|
An attacker with access to the web application with vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "dns.0.server" parameter.
|
An attacker with access to the web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "autorefresh" parameter.
|
A potential attacker with access to the Westermo Lynx device would be able to execute malicious code that could affect the correct functioning of the device. |
An attacker with access to the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "username" parameter in the SNMP configuration.
|
An attacker with access to the network where the affected devices are located could maliciously actions to obtain, via a sniffer, sensitive information exchanged via TCP communications.
|
An attacker with access to the Westermo Lynx web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "forward.0.domain" parameter.
|
The cross-site request forgery token in the request may be predictable or easily guessable allowing attackers to craft a malicious request, which could be triggered by a victim unknowingly. In a successful C...Show more |
3Korenix Pepperl FuchsWestermo29Es7506 Firmware Es7510 Xt FirmwareEs7510 Firmware+26 moreNov 21, 2024 Oct 15, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and...Show more |
Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remote attacker to retrieve the source code of different functions of the web application via requests th...Show more |
1Westermo 3Dr 250 Firmware Dr 260 FirmwareMr 260 FirmwareNov 21, 2024 May 24, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allow CSRF. |
1Westermo 3Dr 250 Firmware Dr 260 FirmwareMr 260 FirmwareNov 21, 2024 May 24, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The /uploadfile? functionality in Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allows remote users to upload malicious file types and execute ASP code. |
1Westermo 3Dr 250 Firmware Dr 260 FirmwareMr 260 FirmwareNov 21, 2024 May 23, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS exists in the /cmdexec/cmdexe?cmd= function in Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers. |
1Westermo 4Mrd 305 Din Firmware Mrd 315 Din FirmwareMrd 355 Din Firmware+1 moreMay 13, 2026 Aug 25, 2017 N/A· v4 5.3 MEDIUM· v3 2.1 LOW· v2 A Use of Hard-Coded Credentials issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The device utilizes hard-coded credentials, which could allow fo...Show more |
1Westermo 4Mrd 305 Din Firmware Mrd 315 Din FirmwareMrd 355 Din Firmware+1 moreMay 13, 2026 Aug 25, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A Cross-Site Request Forgery (CSRF) issue was discovered in Westermo MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The application does not verify whether a request w...Show more |
1Westermo 4Mrd 305 Din Firmware Mrd 315 Din FirmwareMrd 355 Din Firmware+1 moreMay 13, 2026 Aug 25, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Use of Hard-Coded Cryptographic Key issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The device utilizes hard-coded private cryptographic keys...Show more |
Westermo WeOS before 4.19.0 uses the same SSL private key across different customers' installations, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by leveraging knowl...Show more |