Filtered by vendor Logitech Subscriptions
Total 36 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-20636 1 Logitech 2 Lan-w300n\/pr5b, Lan-w300n\/pr5b Firmware 2024-11-21 6.5 Medium
Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/PR5B allows remote attackers to hijack the authentication of administrators via a specially crafted URL. As a result, unintended operations to the device such as changes of the device settings may be conducted.
CVE-2021-20635 1 Logitech 2 Lan-wh450n\/gr, Lan-wh450n\/gr Firmware 2024-11-21 6.5 Medium
Improper restriction of excessive authentication attempts in LOGITEC LAN-WH450N/GR allows an attacker in the wireless range of the device to recover PIN and access the network.
CVE-2019-13055 1 Logitech 4 K360, K360 Firmware, Unifying Receiver and 1 more 2024-11-21 N/A
Certain Logitech Unifying devices allow attackers to dump AES keys and addresses, leading to the capability of live decryption of Radio Frequency transmissions, as demonstrated by an attack against a Logitech K360 keyboard.
CVE-2019-13054 1 Logitech 2 R500, R500 Firmware 2024-11-21 N/A
The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection. On Windows, any text may be injected by using ALT+NUMPAD input to bypass the restriction on the characters A through Z.
CVE-2019-13053 1 Logitech 2 Unifying Receiver, Unifying Receiver Firmware 2024-11-21 N/A
Logitech Unifying devices allow keystroke injection, bypassing encryption. The attacker must press a "magic" key combination while sniffing cryptographic data from a Radio Frequency transmission. NOTE: this issue exists because of an incomplete fix for CVE-2016-10761.
CVE-2019-13052 1 Logitech 2 Unifying Receiver, Unifying Receiver Firmware 2024-11-21 N/A
Logitech Unifying devices allow live decryption if the pairing of a keyboard to a receiver is sniffed.
CVE-2019-12506 1 Logitech 2 R700 Laser Presentation Remote, R700 Laser Presentation Remote Firmware 2024-11-21 N/A
Due to unencrypted and unauthenticated data communication, the wireless presenter Logitech R700 Laser Presentation Remote R-R0010 is prone to keystroke injection attacks. Thus, an attacker is able to send arbitrary keystrokes to a victim's computer system, e.g., to install malware when the target system is unattended. In this way, an attacker can remotely take control over the victim's computer that is operated with an affected receiver of this device.
CVE-2018-15723 1 Logitech 2 Harmony Hub, Harmony Hub Firmware 2024-11-21 N/A
The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request. An unauthenticated remote attacker can leverage this vulnerability to execute application defined commands (e.g. harmony.system?systeminfo).
CVE-2018-15722 1 Logitech 2 Harmony Hub, Harmony Hub Firmware 2024-11-21 N/A
The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request. A remote server or man in the middle can inject OS commands with a properly formatted response.
CVE-2018-15721 1 Logitech 2 Harmony Hub, Harmony Hub Firmware 2024-11-21 N/A
The XMPP server in Logitech Harmony Hub before version 4.15.206 is vulnerable to authentication bypass via a crafted XMPP request. Remote attackers can use this vulnerability to gain access to the local API.
CVE-2018-15720 1 Logitech 2 Harmony Hub, Harmony Hub Firmware 2024-11-21 N/A
Logitech Harmony Hub before version 4.15.206 contained two hard-coded accounts in the XMPP server that gave remote users access to the local API.
CVE-2018-0621 1 Logitech 1 Connection Utility Software 2024-11-21 N/A
Untrusted search path vulnerability in LOGICOOL CONNECTION UTILITY SOFTWARE versions before 2.30.9 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
CVE-2018-0620 1 Logitech 1 Game Software 2024-11-21 N/A
Untrusted search path vulnerability in LOGICOOL Game Software versions before 8.87.116 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
CVE-2016-10761 1 Logitech 10 K360, K360 Firmware, K400r and 7 more 2024-11-21 N/A
Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.
CVE-2024-8258 2 Apple, Logitech 3 Macos, Logi Options\+, Options Plus 2024-09-27 7.8 High
Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options Plus version 1.60.496306 on macOS allows attackers to execute arbitrary code via insecure Electron Fuses configuration.
CVE-2024-8011 1 Logitech 1 Options\+ 2024-09-11 5.5 Medium
Logitech Options+ on MacOS prior 1.72 allows a local attacker to inject dynamic library within Options+ runtime and abuse permissions granted by the user to Options+ such as Camera.