CVE-2025-55972

7.5

TCL · Smart TV

TCL Smart TVs are susceptible to a remote, unauthenticated denial of service attack via malformed UPnP/DLNA SOAP requests, rendering the device unresponsive.

Executive summary

An unauthenticated remote denial of service vulnerability in TCL Smart TVs allows attackers to crash device functionality by flooding the UPnP control endpoint.

Vulnerability

The vulnerability exists within the UPnP/DLNA MediaRenderer implementation. An unauthenticated attacker can send a flood of malformed or oversized SetAVTransportURI SOAP requests to the UPnP control endpoint to induce a persistent denial of service condition.

Business impact

The exploitation of this vulnerability results in a complete loss of device availability, preventing users from operating the television. Given the CVSS score of 7.5, this high severity flaw poses a significant operational risk, particularly in environments where these devices are used for digital signage or public information displays. Continued service disruption may necessitate manual intervention or physical power cycling to restore normal operations.

Remediation

Immediate Action: Contact the vendor or check the official support portal for available firmware updates. If no patch is currently available, disable UPnP services on the device or restrict network access to the UPnP control port via firewall rules.

Proactive Monitoring: Monitor network traffic for unusual spikes in SOAP-related requests originating from untrusted sources. Review device logs for recurring connection errors or service crashes associated with media rendering components.

Compensating Controls: Implement network segmentation to isolate smart devices from the primary corporate network. Use an upstream firewall to block access to UPnP ports from external or unauthorized network segments.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented in the GitHub repository referenced in the CVE record.

Analyst recommendation

Organizations utilizing TCL Smart TVs should treat this vulnerability with high priority, especially in internet-facing configurations. Administrators must restrict network access to UPnP services immediately and prioritize the deployment of vendor-supplied firmware updates as soon as they become available to mitigate the risk of persistent service disruption.

Sources