Yamaha's vulnerability profile centers on a focused line of network routing and connectivity appliances, including models such as the RT57i, RT58i, RTX1000, RTX1100, and RTX1500, which serve as critical infrastructure in enterprise and branch-office networks. The recurring weakness classes reflect the web-management and input-handling attack surface typical of network devices: improper input validation, cross-site request forgery, and output-encoding issues predominate, while a notable share of the vendor's disclosures acquire public exploit code. Defenders should track Yamaha's advisories for its routing portfolio and prioritize patching of internet-exposed management interfaces; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yamaha over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-0356MEDIUM Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connect | May 31, 2005 | 5.0 | 69 | NO | YES |
CVE-2020-5548HIGH Yamaha LTE VoIP Router(NVR700W firmware Rev.15.00.15 and earlier), Yamaha Gigabit VoIP Router(NVR510 firmware Rev.15.01.14 and earlier), Yamaha Gigabit VPN Router(RTX810 firmware R | Apr 1, 2020 | 7.5 | 24 | NO | NO |
CVE-2018-0666MEDIUM Yamaha routers RT57i Rev.8.00.95 and earlier, RT58i Rev.9.01.51 and earlier, NVR500 Rev.11.00.36 and earlier, RTX810 Rev.11.01.31 and earlier, allow an administrative user to embed | Jan 9, 2019 | 6.8 | 23 | NO | NO |
CVE-2011-1323HIGH Yamaha RTX, RT, SRT, RTV, RTW, and RTA series routers with firmware 6.x through 10.x, and NEC IP38X series routers with firmware 6.x through 10.x, do not properly handle IP header | May 9, 2011 | 7.8 | 23 | NO | NO |
CVE-1999-0946MEDIUM Buffer overflow in Yamaha MidiPlug via a Text variable in an EMBED tag. | Nov 2, 1999 | 5.1 | 23 | NO | YES |
CVE-2021-20844MEDIUM Improper neutralization of HTTP request headers for scripting syntax vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.1 | Nov 24, 2021 | 5.7 | 21 | NO | NO |
CVE-2018-0665MEDIUM Yamaha routers RT57i Rev.8.00.95 and earlier, RT58i Rev.9.01.51 and earlier, NVR500 Rev.11.00.36 and earlier, RTX810 Rev.11.01.31 and earlier, allow an administrative user to embed | Jan 9, 2019 | 6.8 | 21 | NO | NO |
CVE-2024-22366MEDIUM Active debug code exists in Yamaha wireless LAN access point devices. If a logged-in user who knows how to use the debug function accesses the device's management page, this functi | Jan 24, 2024 | 6.8 | 20 | NO | NO |
CVE-2021-20843MEDIUM Cross-site script inclusion vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.0 | Nov 24, 2021 | 5.4 | 20 | NO | NO |
CVE-2008-2173HIGH Unspecified vulnerability in Yamaha routers allows remote attackers to cause a denial of service (dropped session) via crafted BGP UPDATE messages, leading to route flapping, possi | May 13, 2008 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yamaha.
Media articles that mention a CVE ID that affects a product developed by Yamaha — matched by CVE ID, not by vendor name.