CVE-2018-15722: Logitech Harmony Hub Firmware

High severity, CVSS 8.1. EPSS: 1.6% chance of exploitation in the next 30 days.

The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request. A remote server or man in the middle can inject OS commands with a properly formatted response.

Affected products

  • Logitech Harmony Hub Firmware: before 4.15.206 (fixed in 4.15.206)

Published 2018-12-20. Last modified 2026-06-17.