Logitech's vulnerability footprint concentrates in a modest but widely deployed portfolio of consumer and prosumer input and control devices, most prominently its Harmony hub and Unifying receiver product lines, which occupy prominent positions in home-automation and wireless-peripheral ecosystems. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a notable tendency to acquire public exploit code; the exposure recurs across web-facing interfaces and firmware components through weakness classes including cross-site scripting, cross-site request forgery, OS command injection, and input-validation gaps that are characteristic of consumer-oriented networked devices. Defenders should prioritize firmware updates for deployed Harmony and Unifying devices, particularly in network-connected environments where command-injection and CSRF chains can amplify risk. Current severity, exploitation, and device inventory counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Logitech over time
Of all the CVEs published by Logitech as a CNA, 83.3% affect products that Logitech develops as a vendor.
Of all the CVEs published that affect products developed by Logitech, 13.9% are self-published by Logitech as a CNA.
Signals from CVEs in this vendor scope (36 CVEs).
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-2918MEDIUM Multiple stack-based buffer overflows in ActiveX controls (1) VibeC in (a) vibecontrol.dll, (2) CallManager and (3) ViewerClient in (b) StarClient.dll, (4) ComLink in (c) uicomlink | Jun 1, 2007 | 6.8 | 59 | NO | YES |
CVE-2012-1250HIGH Logitec LAN-W300N/R routers with firmware before 2.27 do not properly restrict login access, which allows remote attackers to obtain administrative privileges and modify settings v | Jun 4, 2012 | 10.0 | 33 | NO | NO |
CVE-2017-15687MEDIUM DOM Based Cross Site Scripting (XSS) exists in Logitech Media Server 7.7.1, 7.7.2, 7.7.3, 7.7.5, 7.7.6, 7.9.0, and 7.9.1 via a crafted URI. | Oct 23, 2017 | 6.1 | 31 | NO | YES |
CVE-2018-15723CRITICAL The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request. An unauthenticated remote attacker can leverage this | Dec 20, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-15721CRITICAL The XMPP server in Logitech Harmony Hub before version 4.15.206 is vulnerable to authentication bypass via a crafted XMPP request. Remote attackers can use this vulnerability to ga | Dec 20, 2018 | 9.8 | 29 | NO | NO |
CVE-2008-0956HIGH Multiple stack-based buffer overflows in the BackWeb Lite Install Runner ActiveX control in the BackWeb Web Package ActiveX object in LiteInstActivator.dll in BackWeb before 8.1.1. | Jun 12, 2008 | 9.3 | 29 | NO | NO |
CVE-2018-15720CRITICAL Logitech Harmony Hub before version 4.15.206 contained two hard-coded accounts in the XMPP server that gave remote users access to the local API. | Dec 20, 2018 | 9.8 | 28 | NO | NO |
CVE-2017-16568MEDIUM Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Radio" functionality. This vulnerability allows attackers to inject malicious Jav | Nov 10, 2017 | 5.4 | 28 | NO | YES |
CVE-2019-12506HIGH Due to unencrypted and unauthenticated data communication, the wireless presenter Logitech R700 Laser Presentation Remote R-R0010 is prone to keystroke injection attacks. Thus, an | Jun 7, 2019 | 8.8 | 27 | NO | NO |
CVE-2017-16567MEDIUM Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Favorites" feature. This vulnerability allows remote attackers to inject and perm | Nov 10, 2017 | 5.4 | 27 | NO | YES |
Signals from CVEs in this vendor scope (36 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Logitech.
Media articles that mention a CVE ID that affects a product developed by Logitech — matched by CVE ID, not by vendor name.