CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

westermo

l206-f2g_firmware

8 known vulnerabilities · sorted by CVSS score

CVE-2023-45735
HIGH8.0

A potential attacker with access to the Westermo Lynx device may be able to execute malicious code that could affect the correct functioning of the device.

westermo / l206-f2g_firmware
Network
Published Feb 6, 2024
CVE-2023-38579
HIGH8.0

The cross-site request forgery token in the request may be predictable or easily guessable allowing attackers to craft a malicious request, which could be triggered by a victim unknowingly. In a successful CSRF attack, the attacker could lead the victim user to carry out an action unintentionally.

westermo / l206-f2g_firmware
Network
Published Feb 6, 2024
CVE-2023-45213
MEDIUM6.6

A potential attacker with access to the Westermo Lynx device would be able to execute malicious code that could affect the correct functioning of the device.

westermo / l206-f2g_firmware
Adjacent
Published Feb 6, 2024
CVE-2023-40544
MEDIUM5.7

An attacker with access to the network where the affected devices are located could maliciously actions to obtain, via a sniffer, sensitive information exchanged via TCP communications.

westermo / l206-f2g_firmware
Adjacent
Published Feb 6, 2024
CVE-2023-42765
MEDIUM5.4

An attacker with access to the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "username" parameter in the SNMP configuration.

westermo / l206-f2g_firmware
Adjacent
Published Feb 6, 2024
CVE-2023-45222
MEDIUM5.4

An attacker with access to the web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "autorefresh" parameter.

westermo / l206-f2g_firmware
Network
Published Feb 6, 2024
CVE-2023-40143
MEDIUM5.4

An attacker with access to the Westermo Lynx web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "forward.0.domain" parameter.

westermo / l206-f2g_firmware
Network
Published Feb 6, 2024
CVE-2023-45227
MEDIUM5.4

An attacker with access to the web application with vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "dns.0.server" parameter.

westermo / l206-f2g_firmware
Network
Published Feb 6, 2024