Improper URL Scheme Restrictions in Telefunken Smart TV
CVE-2026-15570

7.1HIGH

Key Information:

Vendor

Vestel

Vendor
CVE Published:
7 August 2026

What is CVE-2026-15570?

An issue exists in the Telefunken TE24553B45V2DZ Smart TV where improper restrictions allow the embedded browser to send requests to unauthorized internal destinations, including loopback addresses like 127.0.0.1. This vulnerability can be exploited by an attacker on the same local network, enabling them to access internal services that are otherwise unreachable via conventional browser navigation. The vulnerability is present in firmware version V2.78.0.0, which has been resolved in the subsequent release, version V2.85.2.0.

Affected Version(s)

Telefunken TE24553B45V2DZ Smart TV Vestel MB181 / Voltron181 / TiVo OS V2.78.0.0

Telefunken TE24553B45V2DZ Smart TV Vestel MB181 / Voltron181 / TiVo OS V2.85.2.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Francesco Caligiuri
.