peter bassill · operator
$ cve CVE-2019-12477 JSON

CVE-2019-12477 EXPLOIT

5.5
MEDIUM · CVSS 3.0 · EPSS 13.3% (pctl 96)

Patch early

A public exploit exists.

Description

Supra Smart Cloud TV allows remote file inclusion in the openLiveURL function, which allows a local attacker to broadcast fake video without any authentication via a /remote/media_control?action=setUri&uri= URI.

Scoring

CVSS5.5 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS13.32% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2019-06-07
Last modified2026-06-17

Affected (2)

VendorProduct
suprastv-lc40lt0020f
suprastv-lc40lt0020f firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD