← Back to all advisories
Unranked

Code Execution on Vizio Smart TV from a USB Drive

Advisory ID
L9-44-477
Category
Command Injection
Vendor
Vizio
Product
2017 E50x-E1
Affected Version
6.0.31.4-2, 10.0.31.4-2
First Published
June 28, 2021
Last Updated
January 4, 2024
Impact
Unranked

Risk Summary

The Vizio TV is vulnerable to code execution using a malicious USB device drive-by attack. The Vizio TV does not appropriately segregate the internal web root and USB drive mount location. A threat actor can leverage this weakness to access custom web files including CGI files, that can be leveraged for code execution. A threat actor on the local network can walk up to a Vizio TV, insert a USB drive for a second, and walk away with platform-level code execution to launch further attacks on any connected network.

Technical Details

The researcher created a USB drive which contained a native executable payload, and a CGI file which executes the payload. A static bind shell and CGI file to execute the bind shell are placed on a USB drive.

The USB was inserted into the TV where it was mounted inside the web root. The researcher used the 'Cast All The Things' python library to cast the internal application to the TV, launching the CGI file, and executing the payload.

catt -d TestTV cast_site "http://127.0.0.1:12345/usbparts/sda1/bind.cgi"

Once the script executed, the researcher was able to connect to the payload and execute commands as the root user on both the 2017 E50x-E1 and 2018 P65-F1.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
Platform OverviewDigital TwinAutonomous TestingExploitability VerificationVulnerability GraphRemediation OptimizationELTON TestLink™Lifecycle & MetricsCVSSv4 MigrationProduct Tour
Solutions
FDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLWPostmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory Affairs
Why ELTON
Why ELTONProof Over ProbabilityFind the 1%Not a Pentest. Not a Scanner.MDDT MethodologyCredentialsDevice ModalitiesPricingELTON vs. Consultants
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRegulatory GuidesWebinarsThe Death of PentestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersContact Book a Demo