S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2020-12447 Scanner

CVE-2020-12447 scanner - Local File Inclusion (LFI) vulnerability in Onkyo TX-NR585

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-12447
7.5
CVSS

A Local File Inclusion (LFI) issue on Onkyo TX-NR585 1000-0000-000-0008-0000 devices allows remote unauthenticated users on the network to read sensitive files via %2e%2e%2f directory traversal, as demonstrated by reading /etc/shadow.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Onkyo TX-NR585 is a popular home theater receiver designed to provide high-quality audio and video entertainment. This device delivers powerful and immersive sound, making it ideal for movies, music, and gaming. Its advanced features include support for Dolby Atmos and DTS:X, high-resolution audio playback, and built-in Wi-Fi and Bluetooth connectivity. 

CVE-2020-12447 is a critical security vulnerability discovered in Onkyo TX-NR585 devices. This flaw allows remote attackers to gain access to sensitive files on the device via Local File Inclusion (LFI) attacks. The vulnerability can be exploited by sending specially crafted HTTP requests to the device using a directory traversal technique (%2e%2e%2f). Through this attack, attackers can read files outside of the web root directory, including critical system files such as /etc/shadow, which contains user passwords.

Exploiting this vulnerability can lead to serious consequences, allowing attackers to gain unauthorized access to a target network and steal sensitive data, including login credentials, financial information, and personal data. It is important to note that Onkyo TX-NR585 devices are often connected to a home network, which means that any successful attack can also compromise other devices on the same network.

In conclusion, the discovery of CVE-2020-12447 in Onkyo TX-NR585 devices highlights the importance of maintaining strong cybersecurity practices and keeping devices and software up to date. By using the pro features of the s4e.io platform, users can quickly and easily learn about vulnerabilities in their digital assets and take steps to protect themselves against potential threats.

 

REFERENCES

Solution Advice

There are several precautions that users can take to protect themselves against this vulnerability, including:

  • Applying the latest firmware updates from Onkyo to patch the CVE-2020-12447 vulnerability.
  • Ensuring that the Onkyo TX-NR585 device is not connected directly to the internet and is only accessible via a secure internal network.
  • Implementing strong passwords and changing them regularly.
  • Regularly monitoring network logs and traffic to detect and respond to any suspicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.