CVE-2020-28055: High severity tcl 32s330 vulnerability
A vulnerability in the TCL Android Smart TV series V8-R851T02-LF1 V295 and below and V8-T658T01-LF1 V373 and below by TCL Technology Group Corporation allows a local unprivileged attacker, such as a malicious App, to read & write to the /data/vendor/tcl, /data/vendor/upgrade, and /var/TerminalManager directories within the TV file system. An attacker, such as a malicious APK or local unprivileged user could perform fake system upgrades by writing to the /data/vendor/upgrage folder.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-28055?
CVE-2020-28055 is considered a high-severity vulnerability affecting certain TCL Android Smart TV models.
How do I fix CVE-2020-28055?
To fix CVE-2020-28055, update the affected TCL Android Smart TV firmware to version V8-R851T10-LF1V091 or later.
Which TCL Android Smart TV models are affected by CVE-2020-28055?
TCL Android Smart TV models V8-R851T02-LF1 V295 and below, and V8-T658T01-LF1 V373 and below are affected by CVE-2020-28055.
What are the potential risks associated with CVE-2020-28055?
If exploited, CVE-2020-28055 allows local unprivileged attackers to read and write to sensitive system directories.
Is my TCL Android Smart TV vulnerable if it has been updated?
If your TCL Android Smart TV has been updated to firmware versions greater than V8-R851T10-LF1V091 or V8-T658T01-LF1 V373, it is not vulnerable to CVE-2020-28055.