CVE ID | CVE-2024-11136 |
Publication date | 14 November 2024 |
Vendor | TCL |
Product | Camera |
Vulnerable versions | v6.00.04.0067.3.0 |
Vulnerability type (CWE) | Path Traversal (CWE-35) |
Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in TCL Camera software and participated in coordination of its disclosure.
The default TCL Camera application exposes a provider vulnerable to path traversal vulnerability CVE-2024-11136. Another application can supply malicious URI path and delete arbitrary files from user’s external storage.
After multiple attempts to contact the vendor we did not receive any answer. We suppose this issue affects TCL Camera software in all versions.
Credits
We thank Szymon Chadam for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.