Critical severity9.8NVD Advisory· Published Aug 26, 2021· Updated Jun 17, 2026
CVE-2021-27944
CVE-2021-27944
Description
Several high privileged APIs on the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs do not enforce access controls, allowing an unauthenticated threat actor to access privileged functionality, leading to OS command execution. The specific attack methodology is a file upload.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
56.0.31.4-2+ 1 more
- (no CPE)range: 6.0.31.4-2
- (no CPE)
- Range: 10.0.31.4-2
- cpe:2.3:o:vizio:p65-f1_firmware:6.0.31.4-2:*:*:*:*:*:*:*
- cpe:2.3:o:vizio:e50x-e1_firmware:10.0.31.4-2:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- www.l9group.com/advisories/vizio-tv-unauthenticated-remote-code-executionnvdExploitThird Party Advisory
- www.vizio.comnvdProduct
News mentions
0No linked articles in our index yet.