Onkyo manufactures a range of audio and home-theater receivers, with its vulnerability profile centered on models such as the TX-NR585 and TX-NR686 and their associated firmware components. The recurring weakness class across these disclosures is path traversal, reflecting input-validation issues in the firmware's file-access handling; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Onkyo over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-12447HIGH A Local File Inclusion (LFI) issue on Onkyo TX-NR585 1000-0000-000-0008-0000 devices allows remote unauthenticated users on the network to read sensitive files via %2e%2e%2f direct | Apr 29, 2020 | 7.5 | 34 | NO | YES |
CVE-2019-6113HIGH Directory traversal vulnerability on ONKYO TX-NR686 1030-5000-1040-0010 A/V Receiver devices allows remote attackers to read arbitrary files via a .. (dot dot) and %2f to the defau | Aug 30, 2019 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Onkyo.
Media articles that mention a CVE ID that affects a product developed by Onkyo — matched by CVE ID, not by vendor name.