CVE-2026-15570
Received Received - Intake

Improper URL Scheme Restriction in Telefunken Smart TV

Vulnerability report for CVE-2026-15570, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-07

Last updated on: 2026-08-07

Assigner: 5431be70-064b-4f6a-be51-69eacabef109

Description

An improper restriction of URL schemes and destinations in the SmartCenter browserseturl command in the Telefunken TE24553B45V2DZ Smart TV running on the Vestel MB181 / Voltron181 / TiVo OS platform allows an attacker with access to the same local network to cause the embedded browser to issue requests to unintended loopback/internal destinations, including 127.0.0.1 addresses. In demonstrated scenarios, requests initiated through the SmartCenter browserseturl mechanism could reach an internal service and receive a successful response, although the same destination was not reachable through normal browser navigation. The issue affects firmware version V2.78.0.0 and is fixed in firmware version V2.85.2.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-07
Last Modified
2026-08-07
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
vestel te24553b45v2dz to 2.85.2.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves an improper restriction in the SmartCenter browserseturl command on the Telefunken TE24553B45V2DZ Smart TV running Vestel MB181 / Voltron181 / TiVo OS. It allows attackers on the same local network to manipulate the TV's embedded browser into sending requests to unintended internal destinations, including loopback addresses like 127.0.0.1. The issue was present in firmware version V2.78.0.0 and fixed in V2.85.2.0.

Impact Analysis

An attacker could exploit this to send requests to internal services on your Smart TV that are normally inaccessible. This might allow them to interact with sensitive services, potentially stealing data or executing unauthorized actions. The impact depends on what internal services are running and their security.

Compliance Impact

The vulnerability allows local network attackers to bypass intended browser restrictions and access internal services via loopback addresses. This could lead to unauthorized data exfiltration or manipulation, potentially violating GDPR's data protection requirements and HIPAA's safeguards for protected health information if exploited in healthcare environments.

Mitigation Strategies

Update the TE24553B45V2DZ Smart TV firmware to version V2.85.2.0 or later to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15570. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart