← Back

Westermo

westermo

20 CVEs • 25 products

Products (25)

Click to collapse
Toggle
Weos
weos
Mrd 305 Din
mrd-305-din
Mrd 315 Din
mrd-315-din
Mrd 355 Din
mrd-355-din
Mrd 455 Din
mrd-455-din
Dr 250
dr-250
Dr 260
dr-260
Mr 260
mr-260
Mrd 315
mrd-315
Pmi 110 F2g
pmi-110-f2g
L206 F2g
l206-f2g
L210 F2g
l210-f2g
L210 F2g Lynx
l210-f2g_lynx

CVEs (20)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Westermo
1L210 F2g Lynx Firmware
Jul 30, 2025
Jun 20, 2024
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
An attacker may be able to cause a denial-of-service condition by sending many packets repeatedly.
1Westermo
1L210 F2g Firmware
Jul 30, 2025
Jun 20, 2024
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
An attacker may be able to cause a denial-of-service condition by sending many SSH packets repeatedly.
1Westermo
1L210 F2g Firmware
Jul 30, 2025
Jun 20, 2024
6.9 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
Plain text credentials and session ID can be captured with a network sniffer.
1Westermo
1L206 F2g Firmware
Nov 21, 2024
Feb 6, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
A potential attacker with access to the Westermo Lynx device may be able to execute malicious code that could affect the correct functioning of the device.
1Westermo
1L206 F2g Firmware
Nov 21, 2024
Feb 6, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An attacker with access to the web application with vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "dns.0.server" parameter.
1Westermo
1L206 F2g Firmware
Nov 21, 2024
Feb 6, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An attacker with access to the web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "autorefresh" parameter.
1Westermo
1L206 F2g Firmware
Nov 21, 2024
Feb 6, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A potential attacker with access to the Westermo Lynx device would be able to execute malicious code that could affect the correct functioning of the device.
1Westermo
1L206 F2g Firmware
Nov 21, 2024
Feb 6, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An attacker with access to the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "username" parameter in the SNMP configuration.
1Westermo
1L206 F2g Firmware
Nov 21, 2024
Feb 6, 2024
N/A· v4
5.7 MEDIUM· v3
N/A· v2
An attacker with access to the network where the affected devices are located could maliciously actions to obtain, via a sniffer, sensitive information exchanged via TCP communications.
1Westermo
1L206 F2g Firmware
Nov 21, 2024
Feb 6, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An attacker with access to the Westermo Lynx web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "forward.0.domain" parameter.
1Westermo
1L206 F2g Firmware
Nov 21, 2024
Feb 6, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
The cross-site request forgery token in the request may be predictable or easily guessable allowing attackers to craft a malicious request, which could be triggered by a victim unknowingly. In a successful C...Show more
The cross-site request forgery token in the request may be predictable or easily guessable allowing attackers to craft a malicious request, which could be triggered by a victim unknowingly. In a successful CSRF attack, the attacker could lead the victim user to carry out an action unintentionally. Show less
3Korenix
Pepperl FuchsWestermo
29Es7506 Firmware
Es7510 Xt FirmwareEs7510 Firmware+26 more
Nov 21, 2024
Oct 15, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and...Show more
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below has an active TFTP-Service.Show less
1Westermo
1Mrd 315 Firmware
Nov 21, 2024
Jan 18, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remote attacker to retrieve the source code of different functions of the web application via requests th...Show more
Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remote attacker to retrieve the source code of different functions of the web application via requests that lack certain mandatory parameters. This affects ifaces-diag.asp, system.asp, backup.asp, sys-power.asp, ifaces-wls.asp, ifaces-wls-pkt.asp, and ifaces-wls-pkt-adv.asp.Show less
1Westermo
3Dr 250 Firmware
Dr 260 FirmwareMr 260 Firmware
Nov 21, 2024
May 24, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allow CSRF.
1Westermo
3Dr 250 Firmware
Dr 260 FirmwareMr 260 Firmware
Nov 21, 2024
May 24, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The /uploadfile? functionality in Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allows remote users to upload malicious file types and execute ASP code.
1Westermo
3Dr 250 Firmware
Dr 260 FirmwareMr 260 Firmware
Nov 21, 2024
May 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS exists in the /cmdexec/cmdexe?cmd= function in Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers.
1Westermo
4Mrd 305 Din Firmware
Mrd 315 Din FirmwareMrd 355 Din Firmware+1 more
May 13, 2026
Aug 25, 2017
N/A· v4
5.3 MEDIUM· v3
2.1 LOW· v2
A Use of Hard-Coded Credentials issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The device utilizes hard-coded credentials, which could allow fo...Show more
A Use of Hard-Coded Credentials issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The device utilizes hard-coded credentials, which could allow for unauthorized local low-privileged access to the device.Show less
1Westermo
4Mrd 305 Din Firmware
Mrd 315 Din FirmwareMrd 355 Din Firmware+1 more
May 13, 2026
Aug 25, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A Cross-Site Request Forgery (CSRF) issue was discovered in Westermo MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The application does not verify whether a request w...Show more
A Cross-Site Request Forgery (CSRF) issue was discovered in Westermo MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The application does not verify whether a request was intentionally provided by the user, making it possible for an attacker to trick a user into making a malicious request to the server.Show less
1Westermo
4Mrd 305 Din Firmware
Mrd 315 Din FirmwareMrd 355 Din Firmware+1 more
May 13, 2026
Aug 25, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Use of Hard-Coded Cryptographic Key issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The device utilizes hard-coded private cryptographic keys...Show more
A Use of Hard-Coded Cryptographic Key issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The device utilizes hard-coded private cryptographic keys that may allow an attacker to decrypt traffic from any other source.Show less
1Westermo
1Weos
May 6, 2026
Jan 30, 2016
N/A· v4
9.0 CRITICAL· v3
9.3 HIGH· v2
Westermo WeOS before 4.19.0 uses the same SSL private key across different customers' installations, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by leveraging knowl...Show more
Westermo WeOS before 4.19.0 uses the same SSL private key across different customers' installations, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by leveraging knowledge of a key.Show less