CVE-2018-15723: Logitech Harmony Hub Firmware
Critical severity, CVSS 9.8. EPSS: 3.7% chance of exploitation in the next 30 days.
The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request. An unauthenticated remote attacker can leverage this vulnerability to execute application defined commands (e.g. harmony.system?systeminfo).
Affected products
- Logitech Harmony Hub Firmware: before 4.15.206 (fixed in 4.15.206)
Published 2018-12-20. Last modified 2026-06-17.