Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Logitech

First CVE: Oct 18, 2001Active for: 25 yearsTotal CVEs: 36
28.8
VTI Score
Low

Logitech's vulnerability footprint concentrates in a modest but widely deployed portfolio of consumer and prosumer input and control devices, most prominently its Harmony hub and Unifying receiver product lines, which occupy prominent positions in home-automation and wireless-peripheral ecosystems. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a notable tendency to acquire public exploit code; the exposure recurs across web-facing interfaces and firmware components through weakness classes including cross-site scripting, cross-site request forgery, OS command injection, and input-validation gaps that are characteristic of consumer-oriented networked devices. Defenders should prioritize firmware updates for deployed Harmony and Unifying devices, particularly in network-connected environments where command-injection and CSRF chains can amplify risk. Current severity, exploitation, and device inventory counts are shown alongside this summary.

FAUCET AI Generated
36
Total CVEs
More Total CVEs than 98% of tracked vendors
0.1
Avg CVEs / Product / Year
Bottom 1%
7.3
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Logitech over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 18, 2001
24 years ago
Most Recent CVE
Sep 10, 2024
682 days ago

Self-Reporting Analysis

Of all the CVEs published by Logitech as a CNA, 83.3% affect products that Logitech develops as a vendor.

83.3%
16.7%
Self-reported: 5 (83.3%)
Third-party: 1 (16.7%)

Of all the CVEs published that affect products developed by Logitech, 13.9% are self-published by Logitech as a CNA.

13.9%
86.1%
Self-published: 5 (13.9%)
Other CNAs: 31 (86.1%)

Products(49 total)

Top CVEs

Signals from CVEs in this vendor scope (36 CVEs).

36 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2007-2918MEDIUM
Multiple stack-based buffer overflows in ActiveX controls (1) VibeC in (a) vibecontrol.dll, (2) CallManager and (3) ViewerClient in (b) StarClient.dll, (4) ComLink in (c) uicomlink
Jun 1, 20076.859NOYES
CVE-2012-1250HIGH
Logitec LAN-W300N/R routers with firmware before 2.27 do not properly restrict login access, which allows remote attackers to obtain administrative privileges and modify settings v
Jun 4, 201210.033NONO
CVE-2017-15687MEDIUM
DOM Based Cross Site Scripting (XSS) exists in Logitech Media Server 7.7.1, 7.7.2, 7.7.3, 7.7.5, 7.7.6, 7.9.0, and 7.9.1 via a crafted URI.
Oct 23, 20176.131NOYES
CVE-2018-15723CRITICAL
The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request. An unauthenticated remote attacker can leverage this
Dec 20, 20189.829NONO
CVE-2018-15721CRITICAL
The XMPP server in Logitech Harmony Hub before version 4.15.206 is vulnerable to authentication bypass via a crafted XMPP request. Remote attackers can use this vulnerability to ga
Dec 20, 20189.829NONO
CVE-2008-0956HIGH
Multiple stack-based buffer overflows in the BackWeb Lite Install Runner ActiveX control in the BackWeb Web Package ActiveX object in LiteInstActivator.dll in BackWeb before 8.1.1.
Jun 12, 20089.329NONO
CVE-2018-15720CRITICAL
Logitech Harmony Hub before version 4.15.206 contained two hard-coded accounts in the XMPP server that gave remote users access to the local API.
Dec 20, 20189.828NONO
CVE-2017-16568MEDIUM
Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Radio" functionality. This vulnerability allows attackers to inject malicious Jav
Nov 10, 20175.428NOYES
CVE-2019-12506HIGH
Due to unencrypted and unauthenticated data communication, the wireless presenter Logitech R700 Laser Presentation Remote R-R0010 is prone to keystroke injection attacks. Thus, an
Jun 7, 20198.827NONO
CVE-2017-16567MEDIUM
Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Favorites" feature. This vulnerability allows remote attackers to inject and perm
Nov 10, 20175.427NOYES
View all 36 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products36 CVEs
58%
31%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local6 (16.7%)
Network14 (38.9%)
Unknown5 (13.9%)
Physical0 (0.0%)
Adjacent Network11 (30.6%)
Attack Complexity
Low28 (77.8%)
High3 (8.3%)
Unknown5 (13.9%)
User Interaction
None20 (55.6%)
Unknown5 (13.9%)
Required11 (30.6%)
Privileges Required
Low6 (16.7%)
High3 (8.3%)
None22 (61.1%)
Unknown5 (13.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (36 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.8% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
11.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Logitech.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Logitech — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Logitech's Products

View all 5 CNAs →

Top CWEs