Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Westermo

67 known vulnerabilities

1
CRITICAL
7
HIGH
11
MEDIUM

Top Products

l206-f2g firmware 8 l206-f2g 8 dr-260 firmware 3 dr-260 3 dr-250 firmware 3 dr-250 3 mr-260 firmware 3 mr-260 3 mrd-305-din firmware 3 mrd-305-din 3
19 CVEs
7.5
CVE-2024-35246

An attacker may be able to cause a denial-of-service condition by sending many packets repeatedly.

7.5
CVE-2024-32943

An attacker may be able to cause a denial-of-service condition by sending many SSH packets repeatedly.

5.7
CVE-2024-37183

Plain text credentials and session ID can be captured with a network sniffer.

8.0
CVE-2023-45735

A potential attacker with access to the Westermo Lynx device may be able to execute malicious code that could affec

5.4
CVE-2023-45227

An attacker with access to the web application with vulnerable software could introduce arbitrary JavaScr

5.4
CVE-2023-45222

An attacker with access to the web application that has the vulnerable software could introduce arbitrary JavaScript

6.6
CVE-2023-45213

A potential attacker with access to the Westermo Lynx device would be able to execute malicious code that could a

5.4
CVE-2023-42765

An attacker with access to the vulnerable software could introduce arbitrary JavaScript by injecting a cross-si

5.7
CVE-2023-40544

An attacker with access to the network where the affected devices are located could maliciously actions to ob

5.4
CVE-2023-40143

An attacker with access to the Westermo Lynx web application that has the vulnerable software could introduce arbitrary

8.0
CVE-2023-38579

The cross-site request forgery token in the request may be predictable or easily guessable allowing attacke

6.5
CVE-2020-7227

Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remot

6.5
CVE-2018-19613

Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allow CSRF.

8.8
CVE-2018-19612

The /uploadfile? functionality in Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allows remote users to upload mal

6.1
CVE-2018-19614

XSS exists in the /cmdexec/cmdexe?cmd= function in Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers.

5.3
CVE-2017-12709

A Use of Hard-Coded Credentials issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, M

8.8
CVE-2017-12703

A Cross-Site Request Forgery (CSRF) issue was discovered in Westermo MRD-305-DIN versions older than 1.7.5.0, and MRD-31

7.5
CVE-2016-5816

A Use of Hard-Coded Cryptographic Key issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-

9.0
CVE-2015-7923

Westermo WeOS before 4.19.0 uses the same SSL private key across different customers' installations, which makes it easi

Frequently Asked Questions

How many CVEs affect Westermo?

Westermo has 67 CVE records in our database, including 1 critical and 30 high severity vulnerabilities.

What are the most severe Westermo vulnerabilities?

Westermo has 1 critical severity (CVSS 9.0+) and 30 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Westermo vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Westermo products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Westermo Vulnerabilities

CyberStrike scans your infrastructure for Westermo vulnerabilities and provides real-time remediation guidance.

Get Started