5.5
CVSSv3

CVE-2019-12477

Published: 07/06/2019 Updated: 11/06/2019
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 215
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Supra Smart Cloud TV allows remote file inclusion in the openLiveURL function, which allows a local malicious user to broadcast fake video without any authentication via a /remote/media_control?action=setUri&uri= URI.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

supra stv-lc40lt0020f_firmware -

Exploits

Exploit Title: Remote file inclusion # Date: 03-06-2019 # Exploit Author: Dhiraj Mishra # Vendor Homepage: supraru # Software Link: supraru/catalog/televizory/televizor_supra_stv_lc40lt0020f/ # CVE: CVE-2019-12477 # References: # nvdnistgov/vuln/detail/CVE-2019-12477 # wwwinputzeroio/2019/06/hacking-smart-tvht ...
Supra Smart Cloud TV suffers from an openLiveURL() remote file inclusion vulnerability ...

Recent Articles

Samsung reminds rabble to scan smart TVs for viruses – then tries to make them forget
The Register • Thomas Claburn in San Francisco • 18 Jun 2019

Tweet deleted as telly maker reconsiders damning but refreshingly honest messaging

Samsung on Sunday sent out a tweet urging people to check their Sammy smart TVs for viruses – and then deleted the message, as if someone realized that highlighting the risks posed by connected TVs may be bad for business. The Twitter post, sent via the South Korean manufacturer's @SamsungSupport account, remains preserved for posterity thanks to the Internet Archive's Wayback Machine. "Scanning your computer for malware viruses is important to keep it running smoothly," the message warned. "T...

Supra smart TVs aren't so super smart: Hole lets hackers go all Max Headroom on e-tellies
The Register • Shaun Nichols in San Francisco • 04 Jun 2019

Video streams can be hijacked by anyone on your Wi-Fi Pewdiepie fanboi printer, Chromecast haxxx0r retreats, says they're 'afraid of being caught'

Owners of Supra Smart Cloud TVs are in danger of getting some unwanted programming: it's possible for miscreants or malware on your Wi-Fi network to switch whatever you're watching for video of their or its choosing. Bug-hunter Dhiraj Mishra laid claim to CVE-2019-12477, a remote file inclusion zero-day vulnerability that allows anyone with local network access to specify their own video to display on the TV, overriding whatever is being shown, with no password necessary. As such it's more likel...