CVE-2020-27257: Omron Cx-One

High severity, CVSS 7.8. EPSS: 1.8% chance of exploitation in the next 30 days.

This vulnerability allows local attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can result in a type-confusion condition in the Omron CX-One Version 4.60 and prior devices.

Affected products

  • Omron Cx-One: up to and including 4.60
  • Omron Cx-Position: up to and including 2.52
  • Omron Cx-Protocol: up to and including 2.02
  • Omron Cx-Server: up to and including 5.0.28

Published 2021-02-09. Last modified 2026-06-17.