CVE-2018-13989
HIGHGrundig Smart Inter@ctive TV 3.0 - Cross-Site Request Forgery via TCP Port 8085
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-13989. PoCs published by t4rkd3vilz.
AI-analyzed exploit summary This is a writeup describing a CSRF vulnerability in Grundig Smart Inter@ctive 3.0, where unauthenticated HTTP requests can be sent to control the TV via port 8085. The PoC demonstrates a GET request to trigger a remote control action without authentication.
Description
Grundig Smart Inter@ctive TV 3.0 devices allow CSRF attacks via a POST request to TCP port 8085 containing a predictable ID value, as demonstrated by a /sendrcpackage?keyid=-2544&keysymbol=-4081 request to shut off the device.
Exploits (1)
This is a writeup describing a CSRF vulnerability in Grundig Smart Inter@ctive 3.0, where unauthenticated HTTP requests can be sent to control the TV via port 8085. The PoC demonstrates a GET request to trigger a remote control action without authentication.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H