CVE-2019-6113: Onkyo Tx-NR686 Firmware

High severity, CVSS 7.5. EPSS: 3% chance of exploitation in the next 30 days.

Directory traversal vulnerability on ONKYO TX-NR686 1030-5000-1040-0010 A/V Receiver devices allows remote attackers to read arbitrary files via a .. (dot dot) and %2f to the default URI.

Affected products

  • Onkyo Tx-NR686 Firmware: version 1030-5000-1040-0010 only

Published 2019-08-30. Last modified 2026-06-17.