CVE-2026-15570
Vestel · Telefunken TE24553B45V2DZ Smart TV
A Server-Side Request Forgery (SSRF) vulnerability in the SmartCenter component of the Telefunken TE24553B45V2DZ Smart TV allows local network attackers to trigger unauthorized internal requests.
Executive summary
A high-severity SSRF vulnerability in the Vestel Smart TV platform allows local network attackers to force the device browser to access sensitive internal or loopback destinations.
Vulnerability
This is a Server-Side Request Forgery (CWE-918) vulnerability in the SmartCenter browserseturl command, which fails to restrict the URL schemes and destinations that the browser can visit when triggered by a local network attacker.
Business impact
An attacker on the same local network can use this vulnerability to bypass network security perimeters, potentially interacting with internal services that are otherwise inaccessible from the public internet. Given the CVSS score of 7.1, this poses a risk of unauthorized information gathering or interaction with internal administrative interfaces.
Remediation
Immediate Action: Upgrade the TV firmware to version V2.85.2.0 as provided by the manufacturer.
Proactive Monitoring: Monitor local network traffic for suspicious HTTP requests originating from the Smart TV IP address, particularly those targeting internal IP ranges or 127.0.0.1.
Compensating Controls: Isolate the Smart TV on a separate VLAN or guest network to prevent direct access to internal, sensitive network segments and resources.
Exploitation status
Public Exploit Available: No (exploit_available: false).
Analyst recommendation
Owners of the affected Telefunken Smart TV should apply the provided firmware update immediately. If an update is not immediately feasible, network isolation is strongly recommended to mitigate the risk of local network-based SSRF attacks.