CVE-2019-12477: Supra Stv-LC40LT0020F Firmware

Medium severity, CVSS 5.5. EPSS: 13.3% chance of exploitation in the next 30 days.

Supra Smart Cloud TV allows remote file inclusion in the openLiveURL function, which allows a local attacker to broadcast fake video without any authentication via a /remote/media_control?action=setUri&uri= URI.

Affected products

  • Supra Stv-LC40LT0020F Firmware: affected versions not specified

Published 2019-06-07. Last modified 2026-06-17.