Vulnerabilities > Openwebif Project > High

DATE CVE VULNERABILITY TITLE RISK
2018-12-21 CVE-2018-20332 Path Traversal vulnerability in Openwebif Project Openwebif
An issue has been discovered in the OpenWebif plugin through 1.2.4 for Enigma2 based devices.
network
low complexity
openwebif-project CWE-22
7.5
2017-09-18 CVE-2017-9333 Improper Input Validation vulnerability in Openwebif Project Openwebif 1.2.5
OpenWebif 1.2.5 allows remote code execution via a URL to the CallOPKG function in the IpkgController class in plugin/controllers/ipkg.py, when the URL refers to an attacker-controlled web site with a Trojan horse package.
network
low complexity
openwebif-project CWE-20
8.8