CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “westermo”

16 vulnerabilities found for “westermo”

CVE-2024-35246
HIGH7.5

An attacker may be able to cause a denial-of-service condition by sending many packets repeatedly.

westermo / l210-f2g_lynx_firmware
Network
Published Jun 20, 2024
CVE-2024-32943
HIGH7.5

An attacker may be able to cause a denial-of-service condition by sending many SSH packets repeatedly.

westermo / l210-f2g_firmware
Network
Published Jun 20, 2024
CVE-2024-37183
MEDIUM5.7

Plain text credentials and session ID can be captured with a network sniffer.

westermo / l210-f2g_firmware
Adjacent
Published Jun 20, 2024
CVE-2023-45222
MEDIUM5.4

An attacker with access to the web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "autorefresh" parameter.

westermo / l206-f2g_firmware
Network
Published Feb 6, 2024
CVE-2023-45213
MEDIUM6.6

A potential attacker with access to the Westermo Lynx device would be able to execute malicious code that could affect the correct functioning of the device.

westermo / l206-f2g_firmware
Adjacent
Published Feb 6, 2024
CVE-2023-40143
MEDIUM5.4

An attacker with access to the Westermo Lynx web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "forward.0.domain" parameter.

westermo / l206-f2g_firmware
Network
Published Feb 6, 2024
CVE-2023-42765
MEDIUM5.4

An attacker with access to the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "username" parameter in the SNMP configuration.

westermo / l206-f2g_firmware
Adjacent
Published Feb 6, 2024
CVE-2023-38579
HIGH8.0

The cross-site request forgery token in the request may be predictable or easily guessable allowing attackers to craft a malicious request, which could be triggered by a victim unknowingly. In a successful CSRF attack, the attacker could lead the victim user to carry out an action unintentionally.

westermo / l206-f2g_firmware
Network
Published Feb 6, 2024
CVE-2023-40544
MEDIUM5.7

An attacker with access to the network where the affected devices are located could maliciously actions to obtain, via a sniffer, sensitive information exchanged via TCP communications.

westermo / l206-f2g_firmware
Adjacent
Published Feb 6, 2024
CVE-2023-45227
MEDIUM5.4

An attacker with access to the web application with vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "dns.0.server" parameter.

westermo / l206-f2g_firmware
Network
Published Feb 6, 2024
CVE-2023-45735
HIGH8.0

A potential attacker with access to the Westermo Lynx device may be able to execute malicious code that could affect the correct functioning of the device.

westermo / l206-f2g_firmware
Network
Published Feb 6, 2024
CVE-2020-12504
CRITICAL9.8

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below has an active TFTP-Service.

pepperl-fuchs / es7510-xt_firmware+28
Network
Published Oct 15, 2020
CVE-2020-7227
MEDIUM6.5

Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remote attacker to retrieve the source code of different functions of the web application via requests that lack certain mandatory parameters. This affects ifaces-diag.asp, system.asp, backup.asp, sys-power.asp, ifaces-wls.asp, ifaces-wls-pkt.asp, and ifaces-wls-pkt-adv.asp.

westermo / mrd-315_firmware+1
Network
Published Jan 18, 2020
CVE-2018-19613
MEDIUM6.5

Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allow CSRF.

westermo / dr-260_firmware+2
Network
Published May 24, 2019
CVE-2018-19612
HIGH8.8

The /uploadfile? functionality in Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allows remote users to upload malicious file types and execute ASP code.

westermo / dr-250_firmware+2
Network
Published May 24, 2019
CVE-2018-19614
MEDIUM6.1

XSS exists in the /cmdexec/cmdexe?cmd= function in Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers.

westermo / dr-250_firmware+2
Network
Published May 23, 2019