CVE-2025-55971 describes a blind, unauthenticated Server-Side Request Forgery (SSRF) vulnerability in TCL 65C655 Smart TVs running firmware V8-R75PT01-LF1V269.001116. This flaw allows an attacker to send crafted UPnP MediaRenderer service requests, causing the TV to attempt retrieving attacker-controlled URIs. Rated 4.7 MEDIUM (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L), the vulnerability requires adjacent network access but no authentication or user interaction, potentially enabling internal network probing. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
v8-r75pt01-lf1v269.001116CPE matchmatch criteria | cpe:2.3:o:tcl:65c655_firmware:v8-r75pt01-lf1v269.001116:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.