PT-2026-69040 · Telefunken · Te24553B45V2Dz Smart Tv
CVSS v4.0
7.1
High
| Vector | AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Telefunken TE24553B45V2DZ Smart TV versions prior to V2.85.2.0
Description
Improper restriction of URL schemes and destinations in the SmartCenter
browserseturl command allows an attacker on the same local network to force the embedded browser to send requests to unintended internal or loopback destinations, such as 127.0.0.1. This can enable access to internal services that are otherwise unreachable through standard browser navigation.Recommendations
Update to firmware version V2.85.2.0.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Te24553B45V2Dz Smart Tv