Westermo
67 known vulnerabilities
Top Products
An attacker may be able to cause a denial-of-service condition by sending many packets repeatedly.
An attacker may be able to cause a denial-of-service condition by sending many SSH packets repeatedly.
Plain text credentials and session ID can be captured with a network sniffer.
A potential attacker with access to the Westermo Lynx device may be able to execute malicious code that could affec
An attacker with access to the web application with vulnerable software could introduce arbitrary JavaScr
An attacker with access to the web application that has the vulnerable software could introduce arbitrary JavaScript
A potential attacker with access to the Westermo Lynx device would be able to execute malicious code that could a
An attacker with access to the vulnerable software could introduce arbitrary JavaScript by injecting a cross-si
An attacker with access to the network where the affected devices are located could maliciously actions to ob
An attacker with access to the Westermo Lynx web application that has the vulnerable software could introduce arbitrary
The cross-site request forgery token in the request may be predictable or easily guessable allowing attacke
Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remot
Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allow CSRF.
The /uploadfile? functionality in Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allows remote users to upload mal
XSS exists in the /cmdexec/cmdexe?cmd= function in Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers.
A Use of Hard-Coded Credentials issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, M
A Cross-Site Request Forgery (CSRF) issue was discovered in Westermo MRD-305-DIN versions older than 1.7.5.0, and MRD-31
A Use of Hard-Coded Cryptographic Key issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-
Westermo WeOS before 4.19.0 uses the same SSL private key across different customers' installations, which makes it easi
Frequently Asked Questions
How many CVEs affect Westermo?
Westermo has 67 CVE records in our database, including 1 critical and 30 high severity vulnerabilities.
What are the most severe Westermo vulnerabilities?
Westermo has 1 critical severity (CVSS 9.0+) and 30 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Westermo vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Westermo products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Westermo Vulnerabilities
CyberStrike scans your infrastructure for Westermo vulnerabilities and provides real-time remediation guidance.
Get Started