Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Garmin

First CVE: May 11, 2009Active for: 17 yearsTotal CVEs: 19
36.8
VTI Score
Medium

Garmin's vulnerability profile centers on a modestly represented but prominent portfolio of wearable devices, fitness trackers, and connected applications such as Connect IQ and Forerunner, where firmware and software updates often lag across installed bases. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through memory-safety and authorization weakness classes including classic buffer overflows, integer overflows, improper array indexing, and incorrect authorization checks that are typical of embedded and mobile firmware. Defenders should prioritize inventory of Garmin wearables and connected devices, particularly those in extended service life, and monitor firmware release schedules closely; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
19
Total CVEs
More Total CVEs than 96% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
9.0
Avg CVSS Score
Higher Avg CVSS Score than 87% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Garmin over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 11, 2009
17 years ago
Most Recent CVE
May 13, 2026
72 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-27851CRITICAL
The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attack. Among other uses, the WDU utilizes WebSockets to control
May 13, 20269.330NONO
CVE-2023-23306CRITICAL
The `Toybox.Ant.BurstPayload.add` API method in CIQ API version 2.2.0 through 4.1.7 suffers from a type confusion vulnreability, which can result in an out-of-bounds write operatio
May 23, 20239.830NONO
CVE-2020-27484CRITICAL
Garmin Forerunner 235 before 8.20 is affected by: Integer Overflow. The component is: ConnectIQ TVM. The attack vector is: To exploit the vulnerability, the attacker must upload a
Nov 16, 20209.930NONO
CVE-2023-23305CRITICAL
The GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 is vulnerable to various buffer overflows when loading binary resources. A malicious application embedding special
May 23, 20239.829NONO
CVE-2023-23302CRITICAL
The `Toybox.GenericChannel.setDeviceConfig` API method in CIQ API version 1.2.0 through 4.1.7 does not validate its parameter, which can result in buffer overflows when copying var
May 23, 20239.828NONO
CVE-2023-23300CRITICAL
The `Toybox.Cryptography.Cipher.initialize` API method in CIQ API version 3.0.0 through 4.1.7 does not validate its parameters, which can result in buffer overflows when copying da
May 23, 20239.828NONO
CVE-2023-23298CRITICAL
The `Toybox.Graphics.BufferedBitmap.initialize` API method in CIQ API version 2.3.0 through 4.1.7 does not validate its parameters, which can result in integer overflows when alloc
May 23, 20239.828NONO
CVE-2020-27485CRITICAL
Garmin Forerunner 235 before 8.20 is affected by: Array index error. The component is: ConnectIQ TVM. The attack vector is: To exploit the vulnerability, the attacker must upload a
Nov 16, 20209.928NONO
CVE-2020-27483CRITICAL
Garmin Forerunner 235 before 8.20 is affected by: Array index error. The component is: ConnectIQ TVM. The attack vector is: To exploit the vulnerability, the attacker must upload a
Nov 16, 20209.928NONO
CVE-2023-23303CRITICAL
The `Toybox.Ant.GenericChannel.enableEncryption` API method in CIQ API version 3.2.0 through 4.1.7 does not validate its parameter, which can result in buffer overflows when copyin
May 23, 20239.827NONO
View all 19 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products19 CVEs
26%
68%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (5.3%)
Network17 (89.5%)
Unknown1 (5.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (94.7%)
High0 (0.0%)
Unknown1 (5.3%)
User Interaction
None16 (84.2%)
Unknown1 (5.3%)
Required2 (10.5%)
Privileges Required
Low4 (21.1%)
High0 (0.0%)
None14 (73.7%)
Unknown1 (5.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Garmin.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Garmin — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Garmin's Products

View all 1 CNAs →

Top CWEs