geekmagic-smalltv-ultra
Warn
Audited by Socket on Aug 1, 2026
1 alert found:
SecuritySecurityreferences/device-reference.md
MEDIUMSecurityMEDIUM
references/device-reference.md
No executable/package code is shown here—only documentation/specification. However, the described system design presents a high security risk: an unauthenticated HTTP interface that includes destructive operations (WiFi wipe/reset, file delete/clear, reboot/reset) and an HTTP-accessible firmware update endpoint accepting uploaded binaries. If these endpoints are network-reachable without authentication (as stated), a threat actor could persistently compromise or sabotage the device by installing malicious firmware or by deleting/wiping critical configuration. Treat this as a serious operational takeover risk rather than confirmed malware embedded in this fragment.
Confidence: 60%Severity: 78%
Audit Metadata