Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-55972 PoC — TCL 65C655 Smart TV 安全漏洞

Source
Associated Vulnerability
Title:TCL 65C655 Smart TV 安全漏洞 (CVE-2025-55972)
Description:TCL 65C655 Smart TV是中国TCL公司的一款智能电视。 TCL 65C655 Smart TV存在安全漏洞,该漏洞源于UPnP控制端点容易受到畸形或超大SOAP请求攻击,可能导致拒绝服务。
Description
A TCL Smart TV running a vulnerable UPnP/DLNA MediaRenderer implementation is affected by a remote, unauthenticated Denial of Service (DoS).
Readme
# CVE-2025-55972-Remote-Unauthenticated-Denial-of-Service-DoS-in-TCL-Smart-TV-UPnP-DLNA-AVTransport
A TCL Smart TV running a vulnerable UPnP/DLNA MediaRenderer implementation is affected by a remote, unauthenticated Denial of Service (DoS).

### Vendor: 
TCL Technology Group Corporation

### Product: 
TCL Smart TV (tested: 65C655)

### Vulnerability type: 
Remote Denial of Service (DoS) in UPnP/DLNA MediaRenderer (AVTransport)

### Impact: 
Device become unresponsive or unavailable while the attack persists.

### CVSS v3.1 (Base): 
6.5 (AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

### Discovery date: 
2025-06-28

### CVE: 
CVE-2025-55972

## Description: 
A TCL Smart TV running a vulnerable UPnP/DLNA MediaRenderer implementation is affected by a remote, unauthenticated Denial of Service (DoS). By sending a flood of malformed or oversized SetAVTransportURI SOAP requests to the UPnP control endpoint, an attacker on the local network (or via a forwarded port) can cause the device to become unresponsive. The denial persists while the flood continues and can affect all TV operations; manual control and reboots do not restore functionality until the attack stops.
File Snapshot

[4.0K] /data/pocs/3349a95d5d41b0c1da656c7d1308f88d17a97c7f └── [1.1K] README.md 1 directory, 1 file
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.