Westermo manufactures industrial networking appliances, particularly hardened switches and router products designed for critical infrastructure and remote-site deployment, a narrow but strategically important segment with deep integration into operational technology environments. The vendor's vulnerability exposure concentrates in its L206 switch line and associated firmware, where recurring weakness classes include cross-site scripting, cross-site request forgery, cleartext transmission of credentials, rate-limiting gaps, and hard-coded authentication—patterns typical of embedded web-management interfaces that prioritize availability over defense-in-depth. A meaningful share of the vendor's disclosures reach serious severity, reflecting the sensitivity of industrial control access and the blast radius of flaws in devices that govern traffic for critical systems. Defenders managing Westermo appliances should prioritize network isolation of management interfaces, enforce strong access controls, and treat firmware updates as high-priority in production environments; live severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Westermo over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19612HIGH The /uploadfile? functionality in Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allows remote users to upload malicious file types and execute ASP code. | May 24, 2019 | 8.8 | 28 | NO | NO |
CVE-2017-12703HIGH A Cross-Site Request Forgery (CSRF) issue was discovered in Westermo MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The applica | Aug 25, 2017 | 8.8 | 26 | NO | NO |
CVE-2015-7923CRITICAL Westermo WeOS before 4.19.0 uses the same SSL private key across different customers' installations, which makes it easier for man-in-the-middle attackers to defeat cryptographic p | Jan 30, 2016 | 9.0 | 26 | NO | NO |
CVE-2020-12504CRITICAL Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-X | Oct 15, 2020 | 9.8 | 25 | NO | NO |
CVE-2023-38579HIGH
The cross-site request forgery token in the request may be predictable or easily guessable allowing attackers to craft a malicious request, which could be triggered by | Feb 6, 2024 | 8.8 | 24 | NO | NO |
CVE-2020-7227MEDIUM Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remote attacker to retrieve the source code of different function | Jan 18, 2020 | 6.5 | 23 | NO | NO |
CVE-2016-5816HIGH A Use of Hard-Coded Cryptographic Key issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The device utilize | Aug 25, 2017 | 7.5 | 23 | NO | NO |
CVE-2024-35246HIGH An attacker may be able to cause a denial-of-service condition by sending many packets repeatedly. | Jun 20, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-32943HIGH An attacker may be able to cause a denial-of-service condition by sending many SSH packets repeatedly. | Jun 20, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-45735HIGH
A potential attacker with access to the Westermo Lynx device may be able to execute malicious code that could affect the correct functioning of the device.
| Feb 6, 2024 | 8.0 | 22 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Westermo.
Media articles that mention a CVE ID that affects a product developed by Westermo — matched by CVE ID, not by vendor name.