PT-2018-13784 · Lg · Lg Lnu*+3

Ege Balci

·

Published

2018-09-12

·

Updated

2019-10-03

·

CVE-2018-16946

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions LG LNB*, LND*, LNU*, and LNV* smart network camera devices (affected versions not specified)
Description The issue concerns broken access control in the devices, allowing attackers to download sensitive files without authentication. Specifically, attackers can access /updownload/t.report (also known as Log & Report) files and backup files via download.php. These backup files contain user credentials and configuration information for the camera device. An attacker can discover the backup filename by reading system logs or report data, or by brute-forcing the backup filename pattern. This could potentially allow an attacker to authenticate to the admin account using the admin password.
Recommendations For LG LNB*, LND*, LNU*, and LNV* smart network camera devices, consider restricting access to the download.php endpoint and the /updownload/t.report file to minimize the risk of exploitation. Avoid using default or weak admin passwords, and ensure that all user credentials are securely stored. As a temporary workaround, consider disabling the backup file download feature until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-16946

Affected Products

Lg Lnb*
Lg Lnd*
Lg Lnu*
Lg Lnv*