logo

TV Maker TCL Denies Back Door, Promises Better Process

ID: bf2c2386-0b93-5757-b45c-58a0c4973189

STIX ID: report--bf2c2386-0b93-5757-b45c-58a0c4973189

Feed Name: Security Ledger

Threat Score
50/100

Date Published: 2020-11-20

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

The Security Ledger reports that researchers discovered two serious vulnerabilities in TCL Android-based smart TVs (CVE-2020-27403 and CVE-2020-28055) that allowed unauthenticated browsing of the TV OS and local read/write access to vendor directories; TCL issued a patch for one flaw and committed to patching the other while denying any secret backdoors but acknowledging remote diagnostic/maintenance APKs that can operate device functions when initiated by users. The report highlights which models are affected, notes that some fixes were silently applied via APK updates, and raises broader concerns about privacy and supply-chain risk from consumer devices manufactured or sourced in China.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.