PT-2021-17684 · Vizio · Vizio E50X-E1+1
Published
2021-08-26
·
Updated
2021-09-01
·
CVE-2021-27944
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Vizio P65-F1 version 6.0.31.4-2
Vizio E50x-E1 version 10.0.31.4-2
Description:
The issue concerns several high privileged APIs on Vizio Smart TVs that do not enforce access controls, allowing an unauthenticated threat actor to access privileged functionality. This leads to OS command execution. The specific attack methodology involves a file upload.
Recommendations:
For Vizio P65-F1 version 6.0.31.4-2, consider restricting access to the high privileged APIs until a patch is available.
For Vizio E50x-E1 version 10.0.31.4-2, consider disabling file upload functionality in the affected APIs as a temporary workaround.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vizio E50X-E1
Vizio P65-F1