Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Westermo

First CVE: Jan 30, 2016Active for: 10 yearsTotal CVEs: 22
17.1
VTI Score
Low

Westermo manufactures industrial networking appliances, particularly hardened switches and router products designed for critical infrastructure and remote-site deployment, a narrow but strategically important segment with deep integration into operational technology environments. The vendor's vulnerability exposure concentrates in its L206 switch line and associated firmware, where recurring weakness classes include cross-site scripting, cross-site request forgery, cleartext transmission of credentials, rate-limiting gaps, and hard-coded authentication—patterns typical of embedded web-management interfaces that prioritize availability over defense-in-depth. A meaningful share of the vendor's disclosures reach serious severity, reflecting the sensitivity of industrial control access and the blast radius of flaws in devices that govern traffic for critical systems. Defenders managing Westermo appliances should prioritize network isolation of management interfaces, enforce strong access controls, and treat firmware updates as high-priority in production environments; live severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Westermo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 30, 2016
10 years ago
Most Recent CVE
Jul 20, 2025
369 days ago

Products(25 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-19612HIGH
The /uploadfile? functionality in Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allows remote users to upload malicious file types and execute ASP code.
May 24, 20198.828NONO
CVE-2017-12703HIGH
A Cross-Site Request Forgery (CSRF) issue was discovered in Westermo MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The applica
Aug 25, 20178.826NONO
CVE-2015-7923CRITICAL
Westermo WeOS before 4.19.0 uses the same SSL private key across different customers' installations, which makes it easier for man-in-the-middle attackers to defeat cryptographic p
Jan 30, 20169.026NONO
CVE-2020-12504CRITICAL
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-X
Oct 15, 20209.825NONO
CVE-2023-38579HIGH
The cross-site request forgery token in the request may be predictable or easily guessable allowing attackers to craft a malicious request, which could be triggered by
Feb 6, 20248.824NONO
CVE-2020-7227MEDIUM
Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remote attacker to retrieve the source code of different function
Jan 18, 20206.523NONO
CVE-2016-5816HIGH
A Use of Hard-Coded Cryptographic Key issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The device utilize
Aug 25, 20177.523NONO
CVE-2024-35246HIGH
An attacker may be able to cause a denial-of-service condition by sending many packets repeatedly.
Jun 20, 20247.522NONO
CVE-2024-32943HIGH
An attacker may be able to cause a denial-of-service condition by sending many SSH packets repeatedly.
Jun 20, 20247.522NONO
CVE-2023-45735HIGH
A potential attacker with access to the Westermo Lynx device may be able to execute malicious code that could affect the correct functioning of the device.
Feb 6, 20248.022NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
55%
36%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (4.5%)
Network20 (90.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (4.5%)
Attack Complexity
Low19 (86.4%)
High3 (13.6%)
Unknown0 (0.0%)
User Interaction
None12 (54.5%)
Unknown0 (0.0%)
Required10 (45.5%)
Privileges Required
Low10 (45.5%)
High0 (0.0%)
None12 (54.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Westermo.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Westermo — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Westermo's Products

View all 3 CNAs →

Top CWEs