CVE-2019-12477
MEDIUM 5.5EPSS 13.3%
Supra Smart Cloud TV allows remote file inclusion in the openLiveURL function, which allows a local attacker to broadcast fake video without any authentication via a /remote/media_control?action=setUri&uri= URI.
- CVSS v3.0
- 5.5 MEDIUM
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N - CVSS v2.0
- 2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N - EPSS
- 13.32% chance of exploitation in the next 30 days, 96th percentile
- Published
- 2019-06-07
- Updated
- 2024-08-04