CVE-2020-27403 is a critical information disclosure vulnerability affecting specific TCL Android Smart TV series (V8-R851T02-LF1 V295 and below, V8-T658T01-LF1 V373 and below). An unprivileged attacker on the adjacent network can access an insecure web server on port 7989 (and potentially other ports like 7983), which lists and allows downloading of sensitive system files. This vulnerability has a CVSS score of 6.5 (Medium) due to its low attack complexity and high impact on confidentiality, allowing access to private keys, saved passwords, and other critical data. There is currently no known active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< v8-r851t10-lf1v091CPE matchmatch criteria | cpe:2.3:o:tcl:32s330_firmware:*:*:*:*:*:*:*:* | ||
< v8-r851t10-lf1v091CPE matchmatch criteria | cpe:2.3:o:tcl:40s330_firmware:*:*:*:*:*:*:*:* | ||
< v8-r851t02-lf1v440CPE matchmatch criteria | cpe:2.3:o:tcl:43s434_firmware:*:*:*:*:*:*:*:* | ||
< v8-r851t02-lf1v440CPE matchmatch criteria | cpe:2.3:o:tcl:50s434_firmware:*:*:*:*:*:*:*:* | ||
< v8-r851t02-lf1v440CPE matchmatch criteria | cpe:2.3:o:tcl:55s434_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.