CVE-2020-28055
Summary
| CVE | CVE-2020-28055 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-10 18:15:00 UTC |
| Updated | 2020-12-08 18:38:00 UTC |
| Description | A vulnerability in the TCL Android Smart TV series V8-R851T02-LF1 V295 and below and V8-T658T01-LF1 V373 and below by TCL Technology Group Corporation allows a local unprivileged attacker, such as a malicious App, to read & write to the /data/vendor/tcl, /data/vendor/upgrade, and /var/TerminalManager directories within the TV file system. An attacker, such as a malicious APK or local unprivileged user could perform fake system upgrades by writing to the /data/vendor/upgrage folder. |
Risk And Classification
Problem Types: CWE-732
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Tcl | 32s330 | - | All | All | All |
| Hardware | Tcl | 32s330 | - | All | All | All |
| Operating System | Tcl | 32s330 Firmware | All | All | All | All |
| Operating System | Tcl | 32s330 Firmware | All | All | All | All |
| Hardware | Tcl | 40s330 | - | All | All | All |
| Hardware | Tcl | 40s330 | - | All | All | All |
| Operating System | Tcl | 40s330 Firmware | All | All | All | All |
| Operating System | Tcl | 40s330 Firmware | All | All | All | All |
| Hardware | Tcl | 43s434 | - | All | All | All |
| Hardware | Tcl | 43s434 | - | All | All | All |
| Operating System | Tcl | 43s434 Firmware | All | All | All | All |
| Operating System | Tcl | 43s434 Firmware | All | All | All | All |
| Hardware | Tcl | 50s434 | - | All | All | All |
| Hardware | Tcl | 50s434 | - | All | All | All |
| Operating System | Tcl | 50s434 Firmware | All | All | All | All |
| Operating System | Tcl | 50s434 Firmware | All | All | All | All |
| Hardware | Tcl | 55s434 | - | All | All | All |
| Hardware | Tcl | 55s434 | - | All | All | All |
| Operating System | Tcl | 55s434 Firmware | All | All | All | All |
| Operating System | Tcl | 55s434 Firmware | All | All | All | All |
| Hardware | Tcl | 65s434 | - | All | All | All |
| Hardware | Tcl | 65s434 | - | All | All | All |
| Operating System | Tcl | 65s434 Firmware | All | All | All | All |
| Operating System | Tcl | 65s434 Firmware | All | All | All | All |
| Hardware | Tcl | 75s434 | - | All | All | All |
| Hardware | Tcl | 75s434 | - | All | All | All |
| Operating System | Tcl | 75s434 Firmware | All | All | All | All |
| Operating System | Tcl | 75s434 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| John Jackson (@johnjhacking) | Twitter | MISC | twitter.com | Third Party Advisory |
| TV Maker TCL Denies Back Door, Promises Better Process | The Security Ledger | MISC | securityledger.com | Third Party Advisory |
| security/CVE-2020-27403_CVE-2020-28055_GlobalFAQ.pdf at master · sickcodes/security · GitHub | MISC | github.com | Third Party Advisory |
| TCL — Alert: Vulnerabilities found in TCL Android TVs | MISC | support.tcl.com | Vendor Advisory |
| security/SICK-2020-012.md at master · sickcodes/security · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| CVE-2020-28055 - TCL Android Smart TV (All) - Incorrect Permission Assignment for Critical Vendor Resources - TCL Android TV Vendor Configuration & Upgrade Folders World Writable to Local Attacker - Sick Codes - Linux, NetSec, VPS, Arch, Debian, CentOS Tweaks & Tips! | MISC | sick.codes | Exploit, Third Party Advisory |
| security/CVE-2020-27403_CVE-2020-28055_Press-Statement-and-Questions_11162020.pdf at master · sickcodes/security · GitHub | MISC | github.com | Third Party Advisory |
| JavaScript is not available. | MISC | twitter.com | Third Party Advisory |
| Security Holes Opened Back Door To TCL Android Smart TVs | The Security Ledger | MISC | securityledger.com | Third Party Advisory |
| Extraordinary Vulnerabilities Discovered in TCL Android TVs, Now World’s 3rd Largest TV Manufacturer. - Sick Codes - Linux, NetSec, VPS, Arch, Debian, CentOS Tweaks & Tips! | MISC | sick.codes | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.