Exploitation Summary
EIP tracks 2 public exploits for CVE-2019-12477.
PoCs published by Dhiraj Mishra, Dhiraj Mishra, wvu, including Metasploit module auxiliary/admin/http/supra_smart_cloud_tv_rfi.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in Supra Smart Cloud TV's `openLiveURL` function, allowing unauthenticated attackers to broadcast arbitrary video content via a crafted HTTP request to `/remote/media_control`. The vulnerability is triggered by manipulating the `uri` parameter to point to an attacker-controlled `.m3u8` file.
Description
Supra Smart Cloud TV allows remote file inclusion in the openLiveURL function, which allows a local attacker to broadcast fake video without any authentication via a /remote/media_control?action=setUri&uri= URI.
Exploits (2)
This exploit demonstrates a remote file inclusion vulnerability in Supra Smart Cloud TV's `openLiveURL` function, allowing unauthenticated attackers to broadcast arbitrary video content via a crafted HTTP request to `/remote/media_control`. The vulnerability is triggered by manipulating the `uri` parameter to point to an attacker-controlled `.m3u8` file.
This Metasploit module exploits an unauthenticated remote file inclusion vulnerability in Supra Smart Cloud TV by broadcasting a fake video via a crafted HTTP request. It serves malicious media files to trigger the vulnerability.
References (2)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N