CVE-2020-28055
A vulnerability in the TCL Android Smart TV series V8-R851T02-LF1 V295 and below and V8-T658T01-LF1 V373 and below by TCL Technology Group Corporation allows a local unprivileged attacker, such as a malicious App, to read & write to the /data/vendor/tcl, /data/vendor/upgrade, and /var/TerminalManager directories within the TV file system. An attacker, such as a malicious APK or local unprivileged user could perform fake system upgrades by writing to the /data/vendor/upgrage folder.
Published:Nov 10, 2020
Last Modified:Nov 21, 2024
EPS:Nov 10, 2020
EPSS Score:0.00062
CVSS Score:7.8
Affected Products
Vendor
Product
Action
Vendor
Tcl
Product
32s330
Tcl
32s330
Vendor
Tcl
Product
32s330 Firmware
Tcl
32s330 Firmware
Vendor
Tcl
Product
40s330
Tcl
40s330
Vendor
Tcl
Product
40s330 Firmware
Tcl
40s330 Firmware
Vendor
Tcl
Product
43s434
Tcl
43s434
Vendor
Tcl
Product
43s434 Firmware
Tcl
43s434 Firmware
Vendor
Tcl
Product
50s434
Tcl
50s434
Vendor
Tcl
Product
50s434 Firmware
Tcl
50s434 Firmware
Vendor
Tcl
Product
55s434
Tcl
55s434
Vendor
Tcl
Product
55s434 Firmware
Tcl
55s434 Firmware
Vendor
Tcl
Product
65s434
Tcl
65s434
Vendor
Tcl
Product
65s434 Firmware
Tcl
65s434 Firmware
Vendor
Tcl
Product
75s434
Tcl
75s434
Vendor
Tcl
Product
75s434 Firmware
Tcl
75s434 Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
