Vulnerabilities > Yamaha

DATE CVE VULNERABILITY TITLE RISK
2024-01-24 CVE-2024-22366 OS Command Injection vulnerability in Yamaha products
Active debug code exists in Yamaha wireless LAN access point devices.
low complexity
yamaha CWE-78
6.8
2021-11-24 CVE-2021-20843 Inclusion of Functionality from Untrusted Control Sphere vulnerability in multiple products
Cross-site script inclusion vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier allows a remote authenticated attacker to alter the settings of the product via a specially crafted web page.
network
low complexity
yamaha ntt-west CWE-829
5.4
2021-11-24 CVE-2021-20844 Improper Encoding or Escaping of Output vulnerability in multiple products
Improper neutralization of HTTP request headers for scripting syntax vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier allows a remote authenticated attacker to obtain sensitive information via a specially crafted web page.
network
low complexity
yamaha ntt-west CWE-116
5.7
2020-04-01 CVE-2020-5548 Unspecified vulnerability in Yamaha products
Yamaha LTE VoIP Router(NVR700W firmware Rev.15.00.15 and earlier), Yamaha Gigabit VoIP Router(NVR510 firmware Rev.15.01.14 and earlier), Yamaha Gigabit VPN Router(RTX810 firmware Rev.11.01.33 and earlier, RTX830 firmware Rev.15.02.09 and earlier, RTX1200 firmware Rev.10.01.76 and earlier, RTX1210 firmware Rev.14.01.33 and earlier, RTX3500 firmware Rev.14.00.26 and earlier, and RTX5000 firmware Rev.14.00.26 and earlier), Yamaha Broadband VoIP Router(NVR500 firmware Rev.11.00.38 and earlier), and Yamaha Firewall(FWX120 firmware Rev.11.03.27 and earlier) allow remote attackers to cause a denial of service via unspecified vectors.
network
low complexity
yamaha
7.5
2019-01-09 CVE-2018-0666 Unspecified vulnerability in Yamaha products
Yamaha routers RT57i Rev.8.00.95 and earlier, RT58i Rev.9.01.51 and earlier, NVR500 Rev.11.00.36 and earlier, RTX810 Rev.11.01.31 and earlier, allow an administrative user to embed arbitrary scripts to the configuration data through a certain form field of the configuration page, which may be executed on another administrative user's web browser.
low complexity
yamaha
6.8
2019-01-09 CVE-2018-0665 Unspecified vulnerability in Yamaha products
Yamaha routers RT57i Rev.8.00.95 and earlier, RT58i Rev.9.01.51 and earlier, NVR500 Rev.11.00.36 and earlier, RTX810 Rev.11.01.31 and earlier, allow an administrative user to embed arbitrary scripts to the configuration data through a certain form field of the configuration page, which may be executed on another administrative user's web browser.
low complexity
yamaha
6.8