HIGH · 7.8

CVE-2020-28055

A vulnerability in the TCL Android Smart TV series V8-R851T02-LF1 V295 and below and V8-T658T01-LF1 V373 and below by TCL Technology Group Corporation allows a local unprivileged attacker, such as a m...

Vulnerability Description

A vulnerability in the TCL Android Smart TV series V8-R851T02-LF1 V295 and below and V8-T658T01-LF1 V373 and below by TCL Technology Group Corporation allows a local unprivileged attacker, such as a malicious App, to read & write to the /data/vendor/tcl, /data/vendor/upgrade, and /var/TerminalManager directories within the TV file system. An attacker, such as a malicious APK or local unprivileged user could perform fake system upgrades by writing to the /data/vendor/upgrage folder.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Tcl32S330 Firmware< v8-r851t10-lf1v091
Tcl32S330-
Tcl40S330 Firmware< v8-r851t10-lf1v091
Tcl40S330-
Tcl43S434 Firmware< v8-r851t02-lf1v440
Tcl43S434-
Tcl50S434 Firmware< v8-r851t02-lf1v440
Tcl50S434-
Tcl55S434 Firmware< v8-r851t02-lf1v440
Tcl55S434-
Tcl65S434 Firmware< v8-r851t02-lf1v440
Tcl65S434-
Tcl75S434 Firmware< v8-r851t02-lf1v440
Tcl75S434-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-28055?

CVE-2020-28055 is a vulnerability with a CVSS score of 7.8 (HIGH). A vulnerability in the TCL Android Smart TV series V8-R851T02-LF1 V295 and below and V8-T658T01-LF1 V373 and below by TCL Technology Group Corporation allows a local unprivileged attacker, such as a m...

How severe is CVE-2020-28055?

CVE-2020-28055 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-28055?

Check the references section above for vendor advisories and patch information. Affected products include: Tcl 32S330 Firmware, Tcl 32S330, Tcl 40S330 Firmware, Tcl 40S330, Tcl 43S434 Firmware.