Filtered by vendor Roku Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2018-11314 1 Roku 2 Roku, Roku Firmware 2023-11-07 N/A
The External Control API in Roku and Roku TV products allow unauthorized access via a DNS Rebind attack. This can result in remote device control and privileged device and network information to be exfiltrated by an attacker.
CVE-2022-27152 1 Roku 11 Express, Express 4k\+, Roku Os and 8 more 2023-08-29 5.7 Medium
Roku devices running RokuOS v9.4.0 build 4200 or earlier that uses a Realtek WiFi chip is vulnerable to Arbitrary file modification.