CVE-2020-28055
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
A vulnerability in the TCL Android Smart TV series V8-R851T02-LF1 V295 and below and V8-T658T01-LF1 V373 and below by TCL Technology Group Corporation allows a local unprivileged attacker, such as a malicious App, to read & write to the /data/vendor/tcl, /data/vendor/upgrade, and /var/TerminalManager directories within the TV file system. An attacker, such as a malicious APK or local unprivileged user could perform fake system upgrades by writing to the /data/vendor/upgrage folder.
Una vulnerabilidad en la serie TCL Android Smart TV V8-R851T02-LF1 versiones V295 y por debajo y V8-T658T01-LF1 versiones V373 y por debajo de TCL Technology Group Corporation, permite a un atacante local no privilegiado, tal y como una aplicación maliciosa, leer y escribir en /data/vendor/tcl, /data/vendor/upgrade y /var/TerminalManager dentro del sistema de archivos del TV. Un atacante, como un APK malicioso o un usuario local no privilegiado, podrÃa llevar a cabo actualizaciones del sistema falsas al escribir en la carpeta /data/vendor/upgrade
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-11-02 CVE Reserved
- 2020-11-10 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-732: Incorrect Permission Assignment for Critical Resource
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
https://github.com/sickcodes/security/blob/master/etc/CVE-2020-27403_CVE-2020-28055_GlobalFAQ.pdf | Third Party Advisory | |
https://github.com/sickcodes/security/blob/master/etc/CVE-2020-27403_CVE-2020-28055_Press-Statement-and-Questions_11162020.pdf | Third Party Advisory | |
https://securityledger.com/2020/11/security-holes-opened-back-door-to-tcl-android-smart-tvs | Third Party Advisory | |
https://securityledger.com/2020/11/tv-maker-tcl-denies-back-door-promises-better-process | Third Party Advisory | |
https://twitter.com/johnjhacking | Third Party Advisory | |
https://twitter.com/sickcodes | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.tcl.com/vulnerabilities-found-in-tcl-android-tvs | 2020-12-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Tcl Search vendor "Tcl" | 32s330 Firmware Search vendor "Tcl" for product "32s330 Firmware" | < v8-r851t10-lf1v091 Search vendor "Tcl" for product "32s330 Firmware" and version " < v8-r851t10-lf1v091" | - |
Affected
| in | Tcl Search vendor "Tcl" | 32s330 Search vendor "Tcl" for product "32s330" | - | - |
Safe
|
Tcl Search vendor "Tcl" | 40s330 Firmware Search vendor "Tcl" for product "40s330 Firmware" | < v8-r851t10-lf1v091 Search vendor "Tcl" for product "40s330 Firmware" and version " < v8-r851t10-lf1v091" | - |
Affected
| in | Tcl Search vendor "Tcl" | 40s330 Search vendor "Tcl" for product "40s330" | - | - |
Safe
|
Tcl Search vendor "Tcl" | 43s434 Firmware Search vendor "Tcl" for product "43s434 Firmware" | < v8-r851t02-lf1v440 Search vendor "Tcl" for product "43s434 Firmware" and version " < v8-r851t02-lf1v440" | - |
Affected
| in | Tcl Search vendor "Tcl" | 43s434 Search vendor "Tcl" for product "43s434" | - | - |
Safe
|
Tcl Search vendor "Tcl" | 50s434 Firmware Search vendor "Tcl" for product "50s434 Firmware" | < v8-r851t02-lf1v440 Search vendor "Tcl" for product "50s434 Firmware" and version " < v8-r851t02-lf1v440" | - |
Affected
| in | Tcl Search vendor "Tcl" | 50s434 Search vendor "Tcl" for product "50s434" | - | - |
Safe
|
Tcl Search vendor "Tcl" | 55s434 Firmware Search vendor "Tcl" for product "55s434 Firmware" | < v8-r851t02-lf1v440 Search vendor "Tcl" for product "55s434 Firmware" and version " < v8-r851t02-lf1v440" | - |
Affected
| in | Tcl Search vendor "Tcl" | 55s434 Search vendor "Tcl" for product "55s434" | - | - |
Safe
|
Tcl Search vendor "Tcl" | 65s434 Firmware Search vendor "Tcl" for product "65s434 Firmware" | < v8-r851t02-lf1v440 Search vendor "Tcl" for product "65s434 Firmware" and version " < v8-r851t02-lf1v440" | - |
Affected
| in | Tcl Search vendor "Tcl" | 65s434 Search vendor "Tcl" for product "65s434" | - | - |
Safe
|
Tcl Search vendor "Tcl" | 75s434 Firmware Search vendor "Tcl" for product "75s434 Firmware" | < v8-r851t02-lf1v440 Search vendor "Tcl" for product "75s434 Firmware" and version " < v8-r851t02-lf1v440" | - |
Affected
| in | Tcl Search vendor "Tcl" | 75s434 Search vendor "Tcl" for product "75s434" | - | - |
Safe
|