CVE-2020-11617: Philips DTR3502BFTA Dvb-t2 Firmware

Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.

The RSS application on THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes doesn't validate the SSL certificates of RSS servers, which allows a man-in-the-middle attacker to modify the data delivered to the client.

Affected products

  • Philips DTR3502BFTA Dvb-t2 Firmware: version 2.2.1 only
  • Thomsonstb THT741FTA Firmware: version 2.2.1 only

Published 2020-08-31. Last modified 2026-06-17.