Openwebif Project maintains a web interface application for embedded media systems and set-top boxes, with its small vulnerability footprint concentrated in code-injection, input-validation, path-traversal, and cross-site scripting weaknesses characteristic of web-facing front ends. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openwebif Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9807CRITICAL An issue was discovered in the OpenWebif plugin through 1.2.4 for E2 open devices. The saveConfig function of "plugin/controllers/models/config.py" performs an eval() call on the c | Jun 22, 2017 | 9.8 | 33 | NO | NO |
CVE-2017-9333HIGH OpenWebif 1.2.5 allows remote code execution via a URL to the CallOPKG function in the IpkgController class in plugin/controllers/ipkg.py, when the URL refers to an attacker-contro | Sep 18, 2017 | 8.8 | 26 | NO | NO |
CVE-2018-20332HIGH An issue has been discovered in the OpenWebif plugin through 1.2.4 for Enigma2 based devices. Reading of arbitrary files is possible with /file?action=download&file= followed by a | Dec 21, 2018 | 7.5 | 24 | NO | NO |
CVE-2021-38113MEDIUM In addBouquet in js/bqe.js in OpenWebif (aka e2openplugin-OpenWebif) through 1.4.7, inserting JavaScript into the Add Bouquet feature of the Bouquet Editor (i.e., bouqueteditor/api | Aug 4, 2021 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openwebif Project.
Media articles that mention a CVE ID that affects a product developed by Openwebif Project — matched by CVE ID, not by vendor name.