CVE-2025-55971
MEDIUMTCL 65C655 Smart TV UPnP AVTransport - Unauthenticated Server-Side Request Forgery
Title source: manualDescription
TCL 65C655 Smart TV, running firmware version V8-R75PT01-LF1V269.001116 (Android TV, Kernel 5.4.242+), is vulnerable to a blind, unauthenticated Server-Side Request Forgery (SSRF) vulnerability via the UPnP MediaRenderer service (AVTransport:1). The device accepts unauthenticated SetAVTransportURI SOAP requests over TCP/16398 and attempts to retrieve externally referenced URIs, including attacker-controlled payloads. The blind SSRF allows for sending requests on behalf of the TV, which can be leveraged to probe for other internal or external services accessible by the device (e.g., 127.0.0.1:16XXX, LAN services, or internet targets), potentially enabling additional exploit chains.
References (2)
Core 2
Core References
Scores
CVSS v3
4.7
EPSS
0.0028
EPSS Percentile
19.6%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-918
Status
published
Products (1)
tcl/65c655_firmware
v8-r75pt01-lf1v269.001116
Published
Oct 03, 2025
Tracked Since
Feb 18, 2026