CVE-2025-55972 Details
Description
A TCL Smart TV running a vulnerable UPnP/DLNA MediaRenderer implementation is affected by a remote, unauthenticated Denial of Service (DoS) condition. By sending a flood of malformed or oversized SetAVTransportURI SOAP requests to the UPnP control endpoint, an attacker can cause the device to become unresponsive. This denial persists as long as the attack continues and affects all forms of TV operation. Manual user control and even reboots do not restore functionality unless the flood stops.
A remote, unauthenticated denial-of-service vulnerability has been identified in a TCL Smart TV model 65C655, due to a flawed UPnP/DLNA MediaRenderer implementation. The issue arises when an attacker sends a large volume of malformed or oversized SetAVTransportURI SOAP requests to the UPnP control endpoint. This flood of requests causes the TV to become unresponsive, disrupting all functions. Manual controls and reboots do not restore normal operation until the attack ceases.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 3, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| tcl 65c655 firmware | All versions |
CPE
Remediation
| |
| tcl 65c655 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 16, 2025 | Initial Analysis | [email protected] |
| Oct 3, 2025 | CVE Modified | CISA-ADP |
| Oct 3, 2025 | New CVE Received | [email protected] |