Improper URL Scheme Restrictions in Telefunken Smart TV
CVE-2026-15570
7.1HIGH
Key Information:
- Vendor
Vestel
- Vendor
- CVE Published:
- 7 August 2026
What is CVE-2026-15570?
An issue exists in the Telefunken TE24553B45V2DZ Smart TV where improper restrictions allow the embedded browser to send requests to unauthorized internal destinations, including loopback addresses like 127.0.0.1. This vulnerability can be exploited by an attacker on the same local network, enabling them to access internal services that are otherwise unreachable via conventional browser navigation. The vulnerability is present in firmware version V2.78.0.0, which has been resolved in the subsequent release, version V2.85.2.0.
Affected Version(s)
Telefunken TE24553B45V2DZ Smart TV Vestel MB181 / Voltron181 / TiVo OS V2.78.0.0
Telefunken TE24553B45V2DZ Smart TV Vestel MB181 / Voltron181 / TiVo OS V2.85.2.0
