First published: Fri Sep 14 2018(Updated: )
LG SuperSign CMS allows TVs to be rebooted remotely without authentication via a direct HTTP request to /qsr_server/device/reboot on port 9080.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
LG SuperSign CMS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16706 is a vulnerability in LG SuperSign CMS that allows TVs to be rebooted remotely without authentication.
CVE-2018-16706 has a severity rating of 7.5 (high).
CVE-2018-16706 allows an attacker to reboot LG SuperSign CMS-enabled TVs remotely without authentication by sending a direct HTTP request to /qsr_server/device/reboot on port 9080.
LG SuperSign CMS (version not specified) is affected by CVE-2018-16706.
At the moment, there is no fix available for CVE-2018-16706. It is recommended to apply security measures like network segmentation or firewall rules to limit access to vulnerable TVs.