Linear's vulnerability footprint is centered on a small portfolio of embedded networking and load-balancing appliances, including the LB60Z series, that expose authentication and data-protection concerns. The recurring weakness classes—missing encryption of sensitive data and cross-site scripting in web interfaces—reflect the access-control and input-handling demands of management-facing administrative consoles on network infrastructure devices.
The number and severity of CVEs published that impact products developed by Linear over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-9057HIGH Z-Wave devices based on Silicon Labs 100, 200, and 300 series chipsets do not support encryption, allowing an attacker within radio range to take control of or cause a denial of se | Jan 10, 2022 | 8.8 | 28 | NO | NO |
CVE-2020-9058HIGH Z-Wave devices based on Silicon Labs 500 series chipsets using CRC-16 encapsulation, including but likely not limited to the Linear LB60Z-1 version 3.5, Dome DM501 version 4.26, an | Jan 10, 2022 | 8.1 | 26 | NO | NO |
CVE-2024-52426MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Linear Oy Linear linear allows DOM-Based XSS.This issue affects Linear: from n | Nov 18, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Linear.
Media articles that mention a CVE ID that affects a product developed by Linear — matched by CVE ID, not by vendor name.