Known Vulnerabilities for products from Garmin
Listed below are 19 of the newest known vulnerabilities associated with the vendor "Garmin".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Additional devices specifications by Garmin can be found at device.report : Garmin
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2025-27853 json | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed. The WDU web sit... | Not Provided | 2026-05-13 | 2026-06-02 |
| CVE-2025-27852 json | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a reflected cross site scripting (XSS) attack. Thi... | Not Provided | 2026-05-13 | 2026-06-02 |
| CVE-2025-27851 json | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attack. Am... | Not Provided | 2026-05-13 | 2026-06-02 |
| CVE-2025-27850 json | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a symlink attack. If a malicious graphics package ... | Not Provided | 2026-05-13 | 2026-06-02 |
| CVE-2023-23306 json | The `Toybox.Ant.BurstPayload.add` API method in CIQ API version 2.2.0 through 4.1.7 suffers from a type confusion vulnreabili... | 9.8 - CRITICAL | 2023-05-23 | 2023-05-30 |
| CVE-2023-23305 json | The GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 is vulnerable to various buffer overflows when loading bina... | 9.8 - CRITICAL | 2023-05-23 | 2023-05-30 |
| CVE-2023-23304 json | The GarminOS TVM component in CIQ API version 2.1.0 through 4.1.7 allows applications with a specially crafted head section t... | 9.1 - CRITICAL | 2023-05-23 | 2023-05-30 |
| CVE-2023-23303 json | The `Toybox.Ant.GenericChannel.enableEncryption` API method in CIQ API version 3.2.0 through 4.1.7 does not validate its para... | 9.8 - CRITICAL | 2023-05-23 | 2023-05-30 |
| CVE-2023-23302 json | The `Toybox.GenericChannel.setDeviceConfig` API method in CIQ API version 1.2.0 through 4.1.7 does not validate its parameter... | 9.8 - CRITICAL | 2023-05-23 | 2023-05-30 |
| CVE-2023-23301 json | The `news` MonkeyC operation code in CIQ API version 1.0.0 through 4.1.7 fails to check that string resources are not extendi... | 9.8 - CRITICAL | 2023-05-23 | 2023-05-30 |
| CVE-2023-23300 json | The `Toybox.Cryptography.Cipher.initialize` API method in CIQ API version 3.0.0 through 4.1.7 does not validate its parameter... | 9.8 - CRITICAL | 2023-05-23 | 2023-05-30 |
| CVE-2023-23299 json | The permission system implemented and enforced by the GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 can be by... | 7.5 - HIGH | 2023-05-23 | 2023-05-30 |
| CVE-2023-23298 json | The `Toybox.Graphics.BufferedBitmap.initialize` API method in CIQ API version 2.3.0 through 4.1.7 does not validate its param... | 9.8 - CRITICAL | 2023-05-23 | 2023-05-30 |
| CVE-2022-46081 json | ** DISPUTED ** In Garmin Connect 4.61, terminating a LiveTrack session wouldn't prevent the LiveTrack API from continued expo... | 7.5 - HIGH | 2023-01-04 | 2023-11-07 |
| CVE-2020-27486 json | Garmin Forerunner 235 before 8.20 is affected by: Buffer Overflow. The component is: ConnectIQ TVM. The attack vector is: To ... | 9.9 - CRITICAL | 2020-11-16 | 2020-12-02 |
| CVE-2020-27485 json | Garmin Forerunner 235 before 8.20 is affected by: Array index error. The component is: ConnectIQ TVM. The attack vector is: T... | 9.9 - CRITICAL | 2020-11-16 | 2020-12-02 |
| CVE-2020-27484 json | Garmin Forerunner 235 before 8.20 is affected by: Integer Overflow. The component is: ConnectIQ TVM. The attack vector is: To... | 9.9 - CRITICAL | 2020-11-16 | 2020-12-02 |
| CVE-2020-27483 json | Garmin Forerunner 235 before 8.20 is affected by: Array index error. The component is: ConnectIQ TVM. The attack vector is: T... | 9.9 - CRITICAL | 2020-11-16 | 2020-12-02 |
| CVE-2009-0194 json | The domain-locking implementation in the GARMINAXCONTROL.GarminAxControl_t.1 ActiveX control in npGarmin.dll in the Garmin Co... | Not Provided | 2009-05-11 | 2026-04-23 |
Known software with vulnerabilities from Garmin
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Garmin | Communicator Plugin | 2.6.3 |
| Hardware | Garmin | Forerunner 235 | - |
| Operating System | Garmin | Forerunner 235 Firmware | 8.20 |