« Back to list

Westermo

Westermo Weos: vulnerabilities and CVEs

Westermo Weos has 4 published vulnerabilities, 1 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs4
Last 12 months1
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-46418High (7.6)0.68%—Sep 2, 2026
Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition.
CVE-2025-54319Medium (6.3)0.31%—Jul 20, 2025
An issue was discovered in Westermo WeOS 5 (5.24 through 5.24.4). A threat actor potentially can gain unauthorized access to sensitive information via system logging information (syslog verbose logging that includes…
CVE-2025-46419Medium (5.9)0.37%—Apr 24, 2025
Westermo WeOS 5 through 5.23.0 allows a reboot via a malformed ESP packet.
CVE-2015-7923Critical (9)1.2%—Jan 30, 2016
Westermo WeOS before 4.19.0 uses the same SSL private key across different customers' installations, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by leveraging…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter1
  2. T1203 Exploitation for Client Execution1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Westermo