logitech CVE Vulnerabilities & CVE List (36)

Products (CPE): — CVEs: 36

logitech vulnerability overview

Aggregates CVE and security vulnerability intelligence across all logitech-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk cross-site scripting, vendor risk csrf, vendor risk buffer overflow, and vendor risk path handling and related problems; some flaws may lead to vendor impact session compromise.

Vulnerability distribution trend (last 24 months)

Showing 120 of 36 CVEs
«« First « Prev Page 1 / 2 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2024-8258 Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options Plus version 1.60.496306 on macOS allows attackers to execute arbitrary code via insecure Electron Fuses configuration. [email protected] 2.0 0.16% 2024-09-10 2024-09-27
CVE-2024-8011 Logitech Options+ on MacOS prior 1.72 allows a local attacker to inject dynamic library within Options+ runtime and abuse permissions granted by the user to Options+ such as Camera. [email protected] 2.0 0.04% 2024-08-25 2024-09-11
CVE-2024-2537 Improper Control of Dynamically-Managed Code Resources vulnerability in Logitech Logi Tune on MacOS allows Local Code Inclusion. [email protected] 4.4 0.06% 2024-03-15 2025-04-09
CVE-2022-36263 StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe. An attacker can execute arbitrary code via a crafted .exe file. [email protected] 7.3 0.06% 2022-08-19 2025-06-27
CVE-2022-0916 An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves applications vulnerable to CSRF attacks during authentication and authorization operations. [email protected] 8.4 0.15% 2022-05-03 2024-11-21
CVE-2022-0915 There is a Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability in Logitech Sync for Windows prior to 2.4.574. Successful exploitation of these vulnerabilities may escalate the permission to the system user. [email protected] 6.0 0.04% 2022-04-12 2024-11-21
CVE-2021-38547 Logitech Z120 and S120 speakers through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. The power indicator LED of the speakers is connected directly to the power line, as a result, the intensity of a device's power indicator LED is correlative to the power consumption. The sound played by the speakers affects their power consumption and as a result is also correlative to the light inte [email protected] 5.9 0.29% 2021-08-11 2024-11-21
CVE-2021-20642 Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/RS allows a remote attacker to cause a denial-of-service (DoS) condition by sending a specially crafted URL. [email protected] 6.5 0.42% 2021-02-12 2024-11-21
CVE-2021-20641 Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/RS allows remote attackers to hijack the authentication of administrators via a specially crafted URL. As a result, unintended operations to the device such as changes of the device settings may be conducted. [email protected] 6.5 0.07% 2021-02-12 2024-11-21
CVE-2021-20640 Buffer overflow vulnerability in LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute an arbitrary OS command via unspecified vectors. [email protected] 6.8 0.13% 2021-02-12 2024-11-21
CVE-2021-20639 LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors. [email protected] 6.8 0.34% 2021-02-12 2024-11-21
CVE-2021-20638 LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors. [email protected] 6.8 0.34% 2021-02-12 2024-11-21
CVE-2021-20637 Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/PR5B allows a remote attacker to cause a denial-of-service (DoS) condition by sending a specially crafted URL. [email protected] 6.5 0.42% 2021-02-12 2024-11-21
CVE-2021-20636 Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/PR5B allows remote attackers to hijack the authentication of administrators via a specially crafted URL. As a result, unintended operations to the device such as changes of the device settings may be conducted. [email protected] 6.5 0.07% 2021-02-12 2024-11-21
CVE-2021-20635 Improper restriction of excessive authentication attempts in LOGITEC LAN-WH450N/GR allows an attacker in the wireless range of the device to recover PIN and access the network. [email protected] 6.5 0.09% 2021-02-12 2024-11-21
CVE-2019-13055 Certain Logitech Unifying devices allow attackers to dump AES keys and addresses, leading to the capability of live decryption of Radio Frequency transmissions, as demonstrated by an attack against a Logitech K360 keyboard. [email protected] 6.5 0.10% 2019-06-29 2024-11-21
CVE-2019-13054 The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection. On Windows, any text may be injected by using ALT+NUMPAD input to bypass the restriction on the characters A through Z. [email protected] 6.5 0.03% 2019-06-29 2024-11-21
CVE-2019-13053 Logitech Unifying devices allow keystroke injection, bypassing encryption. The attacker must press a "magic" key combination while sniffing cryptographic data from a Radio Frequency transmission. NOTE: this issue exists because of an incomplete fix for CVE-2016-10761. [email protected] 6.5 0.05% 2019-06-29 2024-11-21
CVE-2019-13052 Logitech Unifying devices allow live decryption if the pairing of a keyboard to a receiver is sniffed. [email protected] 6.5 0.11% 2019-06-29 2024-11-21
CVE-2016-10761 Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack. [email protected] 6.5 0.07% 2019-06-29 2024-11-21
«« First « Prev Page 1 / 2 Next »
cvelogic Threat Intelligence