{ "schema_version": "1.4.0", "id": "GHSA-f4j5-954q-h2r6", "modified": "2022-05-24T19:09:48Z", "published": "2022-05-24T19:09:48Z", "aliases": [ "CVE-2021-27942" ], "details": "Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs allow a threat actor to execute arbitrary code from a USB drive via the Smart Cast functionality, because files on the USB drive are effectively under the web root and can be executed.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-27942" }, { "type": "WEB", "url": "https://www.l9group.com/advisories/vizio-tv-code-execution-from-a-usb-drive" } ], "database_specific": { "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2021-08-03T18:15:00Z" } }