Roku's vulnerability profile centers on its streaming media players and connected camera products, with recurring exposure in input-validation, buffer-overflow, and data-authentication weaknesses characteristic of embedded firmware and media-processing codebases. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Roku over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-11314CRITICAL The External Control API in Roku and Roku TV products allow unauthorized access via a DNS Rebind attack. This can result in remote device control and privileged device and network | Jul 3, 2018 | 9.6 | 27 | NO | NO |
CVE-2023-6324HIGH ThroughTek Kalay SDK uses a predictable PSK value in the DTLS session when encountering an unexpected PSK identity | May 15, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-6322HIGH A stack-based buffer overflow vulnerability exists in the message parsing functionality of the Roku Indoor Camera SE version 3.0.2.4679 and Wyze Cam v3 version 4.36.11.5859. A spec | May 15, 2024 | 8.8 | 25 | NO | NO |
CVE-2022-27152MEDIUM Roku devices running RokuOS v9.4.0 build 4200 or earlier that uses a Realtek WiFi chip is vulnerable to Arbitrary file modification. | Apr 8, 2022 | 5.7 | 21 | NO | NO |
CVE-2023-6323MEDIUM ThroughTek Kalay SDK does not verify the authenticity of received messages, allowing an attacker to impersonate an authoritative server. | May 15, 2024 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Roku.
Media articles that mention a CVE ID that affects a product developed by Roku — matched by CVE ID, not by vendor name.