← Back

Yamaha

yamaha

12 CVEs • 69 products

Products (69)

Click to collapse
Toggle
Rtx1000
rtx1000
Rtx1100
rtx1100
Rtx1500
rtx1500
Rt250i
rt250i
Rt300i
rt300i
Rt57i
rt57i
Rtv700
rtv700
Rtx2000
rtx2000
Rt107e
rt107e
Srt100
srt100
Rt105
rt105
Rt56v
rt56v
Rt58i
rt58i
Rt60w
rt60w
Rt80i
rt80i
Rta50i
rta50i
Rta52i
rta52i
Rta54i
rta54i
Rta55i
rta55i
Rtw65b
rtw65b
Rtw65i
rtw65i
Rtx1200
rtx1200
Rtx3000
rtx3000
Rt52pro
rt52pro
Router
router
Rt100i
rt100i
Rt102i
rt102i
Rt103i
rt103i
Rt105e
rt105e
Rt105i
rt105i
Rt105p
rt105p
Rt140e
rt140e
Rt140f
rt140f
Rt140i
rt140i
Rt140p
rt140p
Rt200i
rt200i
Fwx120
fwx120
Rt140
rt140
Rtx810
rtx810
Midiplug
midiplug
Nvr500
nvr500
Rtx830
rtx830
Nvr510
nvr510
Nvr700w
nvr700w
Rtx1210
rtx1210
Rtx5000
rtx5000
Rtx3500
rtx3500
Wlx222
wlx222
Wlx413
wlx413
Wlx212
wlx212
Wlx313
wlx313
Wlx202
wlx202

CVEs (12)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Yamaha
5Wlx202 Firmware
Wlx212 FirmwareWlx222 Firmware+2 more
Jun 20, 2025
Jan 24, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Active debug code exists in Yamaha wireless LAN access point devices. If a logged-in user who knows how to use the debug function accesses the device's management page, this function can be enabled by performing specific...Show more
Active debug code exists in Yamaha wireless LAN access point devices. If a logged-in user who knows how to use the debug function accesses the device's management page, this function can be enabled by performing specific operations. As a result, an arbitrary OS command may be executed and/or configuration settings of the device may be altered. Affected products and versions are as follows: WLX222 firmware Rev.24.00.03 and earlier, WLX413 firmware Rev.22.00.05 and earlier, WLX212 firmware Rev.21.00.12 and earlier, WLX313 firmware Rev.18.00.12 and earlier, and WLX202 firmware Rev.16.00.18 and earlier.Show less
2Ntt West
Yamaha
8Biz Box Nvr510 Firmware
Biz Box Nvr700w FirmwareBiz Box Rtx1210 Firmware+5 more
Nov 21, 2024
Nov 24, 2021
N/A· v4
5.7 MEDIUM· v3
3.5 LOW· v2
Improper neutralization of HTTP request headers for scripting syntax vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14....Show more
Improper neutralization of HTTP request headers for scripting syntax vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier allows a remote authenticated attacker to obtain sensitive information via a specially crafted web page.Show less
2Ntt West
Yamaha
8Biz Box Nvr510 Firmware
Biz Box Nvr700w FirmwareBiz Box Rtx1210 Firmware+5 more
Nov 21, 2024
Nov 24, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site script inclusion vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier allows a remote authent...Show more
Cross-site script inclusion vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier allows a remote authenticated attacker to alter the settings of the product via a specially crafted web page.Show less
1Yamaha
10Fwx120 Firmware
Nvr500 FirmwareNvr510 Firmware+7 more
Nov 21, 2024
Apr 1, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Yamaha LTE VoIP Router(NVR700W firmware Rev.15.00.15 and earlier), Yamaha Gigabit VoIP Router(NVR510 firmware Rev.15.01.14 and earlier), Yamaha Gigabit VPN Router(RTX810 firmware Rev.11.01.33 and earlier, RTX830 firmware...Show more
Yamaha LTE VoIP Router(NVR700W firmware Rev.15.00.15 and earlier), Yamaha Gigabit VoIP Router(NVR510 firmware Rev.15.01.14 and earlier), Yamaha Gigabit VPN Router(RTX810 firmware Rev.11.01.33 and earlier, RTX830 firmware Rev.15.02.09 and earlier, RTX1200 firmware Rev.10.01.76 and earlier, RTX1210 firmware Rev.14.01.33 and earlier, RTX3500 firmware Rev.14.00.26 and earlier, and RTX5000 firmware Rev.14.00.26 and earlier), Yamaha Broadband VoIP Router(NVR500 firmware Rev.11.00.38 and earlier), and Yamaha Firewall(FWX120 firmware Rev.11.03.27 and earlier) allow remote attackers to cause a denial of service via unspecified vectors.Show less
1Yamaha
4Nvr500 Firmware
Rt57i FirmwareRt58i Firmware+1 more
Nov 21, 2024
Jan 9, 2019
N/A· v4
6.8 MEDIUM· v3
5.2 MEDIUM· v2
Yamaha routers RT57i Rev.8.00.95 and earlier, RT58i Rev.9.01.51 and earlier, NVR500 Rev.11.00.36 and earlier, RTX810 Rev.11.01.31 and earlier, allow an administrative user to embed arbitrary scripts to the configuration...Show more
Yamaha routers RT57i Rev.8.00.95 and earlier, RT58i Rev.9.01.51 and earlier, NVR500 Rev.11.00.36 and earlier, RTX810 Rev.11.01.31 and earlier, allow an administrative user to embed arbitrary scripts to the configuration data through a certain form field of the configuration page, which may be executed on another administrative user's web browser. This is a different vulnerability from CVE-2018-0665.Show less
1Yamaha
4Nvr500 Firmware
Rt57i FirmwareRt58i Firmware+1 more
Nov 21, 2024
Jan 9, 2019
N/A· v4
6.8 MEDIUM· v3
5.2 MEDIUM· v2
Yamaha routers RT57i Rev.8.00.95 and earlier, RT58i Rev.9.01.51 and earlier, NVR500 Rev.11.00.36 and earlier, RTX810 Rev.11.01.31 and earlier, allow an administrative user to embed arbitrary scripts to the configuration...Show more
Yamaha routers RT57i Rev.8.00.95 and earlier, RT58i Rev.9.01.51 and earlier, NVR500 Rev.11.00.36 and earlier, RTX810 Rev.11.01.31 and earlier, allow an administrative user to embed arbitrary scripts to the configuration data through a certain form field of the configuration page, which may be executed on another administrative user's web browser. This is a different vulnerability from CVE-2018-0666.Show less
1Yamaha
14Fwx120
Rt105Rt107e+11 more
Apr 29, 2026
Jan 23, 2014
N/A· v4
N/A· v3
5.4 MEDIUM· v2
The OSPF implementation on Yamaha routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remot...Show more
The OSPF implementation on Yamaha routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.Show less
2Nec
Yamaha
52Ip38x/1000
Ip38x/103Ip38x/105+49 more
Apr 29, 2026
May 9, 2011
N/A· v4
N/A· v3
7.8 HIGH· v2
Yamaha RTX, RT, SRT, RTV, RTW, and RTA series routers with firmware 6.x through 10.x, and NEC IP38X series routers with firmware 6.x through 10.x, do not properly handle IP header options, which allows remote attackers t...Show more
Yamaha RTX, RT, SRT, RTV, RTW, and RTA series routers with firmware 6.x through 10.x, and NEC IP38X series routers with firmware 6.x through 10.x, do not properly handle IP header options, which allows remote attackers to cause a denial of service (device reboot) via a crafted option that triggers access to an invalid memory location.Show less
1Yamaha
1Router
Apr 23, 2026
May 13, 2008
N/A· v4
7.5 HIGH· v3
7.1 HIGH· v2
Unspecified vulnerability in Yamaha routers allows remote attackers to cause a denial of service (dropped session) via crafted BGP UPDATE messages, leading to route flapping, possibly a related issue to CVE-2007-6372.
1Yamaha
18Rt107e
Rt52proRt56v+15 more
Apr 23, 2026
Jan 31, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Cross-site request forgery (CSRF) vulnerability in the management interface in multiple Yamaha RT series routers allows remote attackers to change password settings and probably other configuration settings as administra...Show more
Cross-site request forgery (CSRF) vulnerability in the management interface in multiple Yamaha RT series routers allows remote attackers to change password settings and probably other configuration settings as administrators via unspecified vectors.Show less
9Alaxala
CiscoF5+6 more
767220 Wlan Access Point
7250 Wlan Access PointAgent Desktop+73 more
Apr 16, 2026
May 31, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a la...Show more
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.Show less
1Yamaha
1Midiplug
Apr 16, 2026
Nov 2, 1999
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Buffer overflow in Yamaha MidiPlug via a Text variable in an EMBED tag.