CVE-2021-27943

HIGH

Vizio P65-F1 and E50x-E1 Firmware - Unauthenticated Brute-Force Pairing Attack

Title source: llm
STIX 2.1

Description

The pairing procedure used by the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs and mobile application is vulnerable to a brute-force attack (against only 10000 possibilities), allowing a threat actor to forcefully pair the device, leading to remote control of the TV settings and configurations.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://www.vizio.com

Scores

CVSS v3 7.5
EPSS 0.0092
EPSS Percentile 55.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-307
Status published
Products (2)
vizio/e50x-e1_firmware 10.0.31.4-2
vizio/p65-f1_firmware 6.0.31.4-2
Published Aug 02, 2021
Tracked Since Feb 18, 2026