Sony Bravia Smart TV devices allow remote attackers to retrieve the static Wi-Fi password (used when the TV is acting as an access point) by using the Photo Sharing Plus application to execute a backdoor API command, a different vulnerability than CVE-2019-10886.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
http://seclists.org/fulldisclosure/2019/Apr/32 | mailing list exploit third party advisory |
http://packetstormsecurity.com/files/152612/Sony-Smart-TV-Information-Disclosure-File-Read.html | exploit vdb entry third party advisory |
https://seclists.org/bugtraq/2019/Apr/34 | mailing list exploit third party advisory |
http://www.securityfocus.com/bid/108072 | vdb entry third party advisory |
https://www.darkmatter.ae/xen1thlabs/sony-smart-tv-photo-sharing-plus-information-disclosure-vulnerability-xl-19-003/ | third party advisory exploit |