CVE-2025-55972: High severity Tcl 65c655 Firmware vulnerability
A TCL Smart TV running a vulnerable UPnP/DLNA MediaRenderer implementation is affected by a remote, unauthenticated Denial of Service (DoS) condition. By sending a flood of malformed or oversized SetAVTransportURI SOAP requests to the UPnP control endpoint, an attacker can cause the device to become unresponsive. This denial persists as long as the attack continues and affects all forms of TV operation. Manual user control and even reboots do not restore functionality unless the flood stops.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55972?
CVE-2025-55972 is classified as a remote unauthenticated Denial of Service (DoS) vulnerability.
How do I fix CVE-2025-55972?
To mitigate CVE-2025-55972, users should disable UPnP and DLNA functionalities on their TCL Smart TVs until a firmware update is available.
Which devices are affected by CVE-2025-55972?
CVE-2025-55972 affects TCL Smart TVs running the vulnerable UPnP/DLNA MediaRenderer implementation, specifically the Tcl 65C655 firmware.
What exploitation method is used in CVE-2025-55972?
CVE-2025-55972 can be exploited by sending a flood of malformed or oversized SetAVTransportURI SOAP requests to the UPnP control endpoint.
Can CVE-2025-55972 be exploited remotely?
Yes, CVE-2025-55972 allows for remote exploitation without authentication, making it particularly dangerous.