CVE-2025-55972
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-10-03

Last updated on: 2025-10-16

Assigner: MITRE

Description
A TCL Smart TV running a vulnerable UPnP/DLNA MediaRenderer implementation is affected by a remote, unauthenticated Denial of Service (DoS) condition. By sending a flood of malformed or oversized SetAVTransportURI SOAP requests to the UPnP control endpoint, an attacker can cause the device to become unresponsive. This denial persists as long as the attack continues and affects all forms of TV operation. Manual user control and even reboots do not restore functionality unless the flood stops.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-10-03
Last Modified
2025-10-16
Generated
2026-05-07
AI Q&A
2025-10-03
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
tcl 65c655_firmware *
tcl 65c655 *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability affects TCL Smart TVs with a vulnerable UPnP/DLNA MediaRenderer implementation. An attacker can send a flood of malformed or oversized SetAVTransportURI SOAP requests to the TV's UPnP control endpoint, causing the device to become unresponsive. This results in a remote, unauthenticated Denial of Service (DoS) condition that persists as long as the attack continues.


How can this vulnerability impact me? :

The vulnerability can cause your TCL Smart TV to become completely unresponsive, affecting all forms of TV operation. Manual user control and even rebooting the device will not restore functionality until the attack stops, effectively denying you the use of the TV during the attack.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart