PT-2018-13784 · Lg · Lg Lnu*+3
Ege Balci
·
Published
2018-09-12
·
Updated
2019-10-03
·
CVE-2018-16946
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
LG LNB*, LND*, LNU*, and LNV* smart network camera devices (affected versions not specified)
Description
The issue concerns broken access control in the devices, allowing attackers to download sensitive files without authentication. Specifically, attackers can access
/updownload/t.report (also known as Log & Report) files and backup files via download.php. These backup files contain user credentials and configuration information for the camera device. An attacker can discover the backup filename by reading system logs or report data, or by brute-forcing the backup filename pattern. This could potentially allow an attacker to authenticate to the admin account using the admin password.Recommendations
For LG LNB*, LND*, LNU*, and LNV* smart network camera devices, consider restricting access to the
download.php endpoint and the /updownload/t.report file to minimize the risk of exploitation. Avoid using default or weak admin passwords, and ensure that all user credentials are securely stored. As a temporary workaround, consider disabling the backup file download feature until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lg Lnb*
Lg Lnd*
Lg Lnu*
Lg Lnv*