Vulnerabilities > Logitech > High

DATE CVE VULNERABILITY TITLE RISK
2022-08-19 CVE-2022-36263 Unspecified vulnerability in Logitech Streamlabs Desktop 1.9.0
StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe.
local
low complexity
logitech
7.3
2021-02-12 CVE-2021-20639 OS Command Injection vulnerability in Logitech Lan-W300N/Pgrb Firmware
LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.
low complexity
logitech CWE-78
7.7
2021-02-12 CVE-2021-20638 OS Command Injection vulnerability in Logitech Lan-W300N/Pgrb Firmware
LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.
low complexity
logitech CWE-78
7.7
2019-06-07 CVE-2019-12506 Missing Authentication for Critical Function vulnerability in Logitech R700 Laser Presentation Remote Firmware Wd802Xm/Wd904Xm
Due to unencrypted and unauthenticated data communication, the wireless presenter Logitech R700 Laser Presentation Remote R-R0010 is prone to keystroke injection attacks.
low complexity
logitech CWE-306
8.3
2018-12-20 CVE-2018-15723 Unspecified vulnerability in Logitech Harmony HUB Firmware
The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request.
network
low complexity
logitech
7.5
2018-12-20 CVE-2018-15721 Improper Authentication vulnerability in Logitech Harmony HUB Firmware
The XMPP server in Logitech Harmony Hub before version 4.15.206 is vulnerable to authentication bypass via a crafted XMPP request.
network
low complexity
logitech CWE-287
7.5
2018-12-20 CVE-2018-15720 Use of Hard-coded Credentials vulnerability in Logitech Harmony HUB Firmware
Logitech Harmony Hub before version 4.15.206 contained two hard-coded accounts in the XMPP server that gave remote users access to the local API.
network
low complexity
logitech CWE-798
7.5