Vulnerabilities (CVE)

Filtered by vendor Roku Subscribe
Filtered by product Roku Firmware
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-11314 1 Roku 2 Roku, Roku Firmware 2024-02-28 9.3 HIGH 9.6 CRITICAL
The External Control API in Roku and Roku TV products allow unauthorized access via a DNS Rebind attack. This can result in remote device control and privileged device and network information to be exfiltrated by an attacker.