PT-2021-17682 · Vizio · Vizio E50X-E1+1

Published

2021-08-03

·

Updated

2021-08-11

·

CVE-2021-27942

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Vizio P65-F1 version 6.0.31.4-2 Vizio E50x-E1 version 10.0.31.4-2
Description: The issue allows a threat actor to execute arbitrary code from a USB drive via the Smart Cast functionality. This is possible because files on the USB drive are effectively under the web root and can be executed.
Recommendations: For Vizio P65-F1 version 6.0.31.4-2, consider disabling the Smart Cast functionality until a patch is available. For Vizio E50x-E1 version 10.0.31.4-2, consider disabling the Smart Cast functionality until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-27942

Affected Products

Vizio E50X-E1
Vizio P65-F1