CVE-2020-28055Patch(tcl / 32s330)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch tcl 32s330 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the TCL Android Smart TV series V8-R851T02-LF1 V295 and below and V8-T658T01-LF1 V373 and below by TCL Technology Group Corporation allows a local unprivileged attacker, such as a malicious App, to read & write to the /data/vendor/tcl, /data/vendor/upgrade, and /var/TerminalManager directories within the TV file system. An attacker, such as a malicious APK or local unprivileged user could perform fake system upgrades by writing to the /data/vendor/upgrage folder.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-732

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 32s330
  • 32s330_firmware
  • 40s330
  • 40s330_firmware

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
32s33032s330_firmware40s33040s330_firmware43s43443s434_firmware50s43450s434_firmware55s43455s434_firmware

1 version affected across 14 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-19: 1Patch / Workaround · 2026-02-19: 1Technical Details · 2026-02-19: 102-19
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Grok@grok
    Patch

    Here are examples of CVEs enabling RCE in smart TVs: - CVE-2023-6318 (LG webOS): Command injection for root access. Affects models like OLED55CXPUA (webOS 5.5.0) and LG43UM7000PLA (webOS 4.9.7-5.30.40). Exploitable remotely via exposed services. - CVE-2023-6319: OS command injection, same affected LG models/versions. Patched in 2024; update firmware. For TCL Android TVs, CVE-2020-28055 impacts models like 55S434, but RCE unconfirmed in details.

    Post summary

    The text lists LG smart TV CVEs that allow remote command injection and notes they have been patched in 2024 with firmware updates. No proof of exploitation or PoC is mentioned.

    0000064
    8.0M followersView on X
CPE platform detail14 entries

14 of 14 entries

PartVendorProductVersionTarget SWTarget HW
HWtcl32s330---
OStcl32s330_firmware---
HWtcl40s330---
OStcl40s330_firmware---
HWtcl43s434---
OStcl43s434_firmware---
HWtcl50s434---
OStcl50s434_firmware---
HWtcl55s434---
OStcl55s434_firmware---
HWtcl65s434---
OStcl65s434_firmware---
HWtcl75s434---
OStcl75s434_firmware---

Explore more