Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

L210 F2g Lynx Firmware HIGH 7.5
CVE-2024-35246

An attacker may be able to cause a denial-of-service condition by sending many packets repeatedly.

No fix yet
Fix from $1,950 2024-06-20
L210 F2g Firmware HIGH 7.5
CVE-2024-32943

An attacker may be able to cause a denial-of-service condition by sending many SSH packets repeatedly.

No fix yet
Fix from $1,950 2024-06-20
L210 F2g Firmware HIGH 7.5
CVE-2024-37183

Plain text credentials and session ID can be captured with a network sniffer.

Mitigation only
Fix from $1,950 2024-06-20
L206 F2g Firmware HIGH 8.0
CVE-2023-45735

A potential attacker with access to the Westermo Lynx device may be able to execute malicious code that could affect the correct functioning of the d…

No fix yet
Fix from $1,950 2024-02-06
L206 F2g Firmware MEDIUM 5.4
CVE-2023-45227

An attacker with access to the web application with vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payl…

Mitigation only
Fix from $1,600 2024-02-06
L206 F2g Firmware MEDIUM 6.5
CVE-2023-45213

A potential attacker with access to the Westermo Lynx device would be able to execute malicious code that could affect the correct functioning of the…

No fix yet
Fix from $1,600 2024-02-06
L206 F2g Firmware MEDIUM 5.7
CVE-2023-40544

An attacker with access to the network where the affected devices are located could maliciously actions to obtain, via a sniffer, sensitive informati…

Mitigation only
Fix from $1,600 2024-02-06
L206 F2g Firmware MEDIUM 5.4
CVE-2023-40143

An attacker with access to the Westermo Lynx web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cro…

Mitigation only
Fix from $1,600 2024-02-06
L206 F2g Firmware MEDIUM 5.4
CVE-2023-42765

An attacker with access to the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "usernam…

Mitigation only
Fix from $1,600 2024-02-06
L206 F2g Firmware MEDIUM 5.4
CVE-2023-45222

An attacker with access to the web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site script…

Mitigation only
Fix from $1,600 2024-02-06
L206 F2g Firmware HIGH 8.8
CVE-2023-38579

The cross-site request forgery token in the request may be predictable or easily guessable allowing attackers to craft a malicious request, which cou…

Mitigation only
Fix from $1,950 2024-02-06
Mrd 315 Firmware MEDIUM 6.5
CVE-2020-7227

Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remote attacker to retrieve the so…

No fix yet
Fix from $1,600 2020-01-18
Dr 250 Firmware HIGH 8.8
CVE-2018-19612

The /uploadfile? functionality in Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allows remote users to upload malicious file types and execute…

Mitigation only
Fix from $1,950 2019-05-24
Dr 260 Firmware MEDIUM 6.5
CVE-2018-19613

Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allow CSRF.

No fix yet
Fix from $1,600 2019-05-24
Dr 250 Firmware MEDIUM 6.1
CVE-2018-19614

XSS exists in the /cmdexec/cmdexe?cmd= function in Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers.

Mitigation only
Fix from $1,600 2019-05-23
Mrd 305 Din Firmware HIGH 8.8
CVE-2017-12703

A Cross-Site Request Forgery (CSRF) issue was discovered in Westermo MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions …

Mitigation only
Fix from $1,950 2017-08-25
Mrd 305 Din Firmware HIGH 7.5
CVE-2016-5816

A Use of Hard-Coded Cryptographic Key issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older t…

Mitigation only
Fix from $1,950 2017-08-25
Mrd 305 Din Firmware MEDIUM 5.3
CVE-2017-12709

A Use of Hard-Coded Credentials issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.…

Mitigation only
Fix from $1,600 2017-08-25
Weos CRITICAL 9.0
CVE-2015-7923

Westermo WeOS before 4.19.0 uses the same SSL private key across different customers' installations, which makes it easier for man-in-the-middle atta…

Mitigation only
Fix from $2,300 2016-01-30