CVE-2020-12447: Onkyo Tx-NR585 Firmware
High severity, CVSS 7.5. EPSS: 13.7% chance of exploitation in the next 30 days.
A Local File Inclusion (LFI) issue on Onkyo TX-NR585 1000-0000-000-0008-0000 devices allows remote unauthenticated users on the network to read sensitive files via %2e%2e%2f directory traversal, as demonstrated by reading /etc/shadow.
Affected products
- Onkyo Tx-NR585 Firmware: version 1000-0000-000-0008-0000 only
Published 2020-04-29. Last modified 2026-06-17.