PT-2021-17684 · Vizio · Vizio E50X-E1+1

Published

2021-08-26

·

Updated

2021-09-01

·

CVE-2021-27944

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Vizio P65-F1 version 6.0.31.4-2 Vizio E50x-E1 version 10.0.31.4-2
Description: The issue concerns several high privileged APIs on Vizio Smart TVs that do not enforce access controls, allowing an unauthenticated threat actor to access privileged functionality. This leads to OS command execution. The specific attack methodology involves a file upload.
Recommendations: For Vizio P65-F1 version 6.0.31.4-2, consider restricting access to the high privileged APIs until a patch is available. For Vizio E50x-E1 version 10.0.31.4-2, consider disabling file upload functionality in the affected APIs as a temporary workaround.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-27944

Affected Products

Vizio E50X-E1
Vizio P65-F1