目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2025-55972 PoC — TCL 65C655 Smart TV 安全漏洞

来源
关联漏洞
标题: TCL 65C655 Smart TV 安全漏洞 (CVE-2025-55972)
Description:TCL 65C655 Smart TV是中国TCL公司的一款智能电视。 TCL 65C655 Smart TV存在安全漏洞,该漏洞源于UPnP控制端点容易受到畸形或超大SOAP请求攻击,可能导致拒绝服务。
Description
A TCL Smart TV running a vulnerable UPnP/DLNA MediaRenderer implementation is affected by a remote, unauthenticated Denial of Service (DoS).
介绍
# CVE-2025-55972-Remote-Unauthenticated-Denial-of-Service-DoS-in-TCL-Smart-TV-UPnP-DLNA-AVTransport
A TCL Smart TV running a vulnerable UPnP/DLNA MediaRenderer implementation is affected by a remote, unauthenticated Denial of Service (DoS).

### Vendor: 
TCL Technology Group Corporation

### Product: 
TCL Smart TV (tested: 65C655)

### Vulnerability type: 
Remote Denial of Service (DoS) in UPnP/DLNA MediaRenderer (AVTransport)

### Impact: 
Device become unresponsive or unavailable while the attack persists.

### CVSS v3.1 (Base): 
6.5 (AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

### Discovery date: 
2025-06-28

### CVE: 
CVE-2025-55972

## Description: 
A TCL Smart TV running a vulnerable UPnP/DLNA MediaRenderer implementation is affected by a remote, unauthenticated Denial of Service (DoS). By sending a flood of malformed or oversized SetAVTransportURI SOAP requests to the UPnP control endpoint, an attacker on the local network (or via a forwarded port) can cause the device to become unresponsive. The denial persists while the flood continues and can affect all TV operations; manual control and reboots do not restore functionality until the attack stops.
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →