← Back

Openelec

openelec

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Openelec
openelec

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openelec
1Openelec
May 13, 2026
Mar 5, 2017
N/A· v4
8.1 HIGH· v3
7.6 HIGH· v2
The auto-update feature of Open Embedded Linux Entertainment Center (OpenELEC) 6.0.3, 7.0.1, and 8.0.4 uses neither encrypted connections nor signed updates. A man-in-the-middle attacker could manipulate the update packa...Show more
The auto-update feature of Open Embedded Linux Entertainment Center (OpenELEC) 6.0.3, 7.0.1, and 8.0.4 uses neither encrypted connections nor signed updates. A man-in-the-middle attacker could manipulate the update packages to gain root access remotely.Show less
1Openelec
1Openelec
May 6, 2026
Feb 8, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
OpenELEC and RasPlex devices have a hardcoded password for the root account, which makes it easier for remote attackers to obtain access via an SSH session.
1Openelec
1Openelec
Apr 23, 2026
Feb 3, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Directory traversal vulnerability in scr/form.php in openElec 3.01 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the obj parameter.