← Back

P65 F1 Firmware

p65-f1_firmware

Vendor: Vizio • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Vizio
2E50x E1 Firmware
P65 F1 Firmware
Nov 21, 2024
Aug 26, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Several high privileged APIs on the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs do not enforce access controls, allowing an unauthenticated threat actor to access privileged functionality, leading to OS com...Show more
Several high privileged APIs on the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs do not enforce access controls, allowing an unauthenticated threat actor to access privileged functionality, leading to OS command execution. The specific attack methodology is a file upload.Show less
1Vizio
2E50x E1 Firmware
P65 F1 Firmware
Nov 21, 2024
Aug 3, 2021
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs allow a threat actor to execute arbitrary code from a USB drive via the Smart Cast functionality, because files on the USB drive are effectively under the web roo...Show more
Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs allow a threat actor to execute arbitrary code from a USB drive via the Smart Cast functionality, because files on the USB drive are effectively under the web root and can be executed.Show less
1Vizio
2E50x E1 Firmware
P65 F1 Firmware
Nov 21, 2024
Aug 2, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The pairing procedure used by the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs and mobile application is vulnerable to a brute-force attack (against only 10000 possibilities), allowing a threat actor to forc...Show more
The pairing procedure used by the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs and mobile application is vulnerable to a brute-force attack (against only 10000 possibilities), allowing a threat actor to forcefully pair the device, leading to remote control of the TV settings and configurations.Show less