CVE-2018-16706: High severity lg supersign cms vulnerability
Published Sep 14, 2018
·Updated
LG SuperSign CMS allows TVs to be rebooted remotely without authentication via a direct HTTP request to /qsrserver/device/reboot on port 9080.
Affected Software
1 affected component
LG SuperSign CMS
Event History
Sep 14, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-16706?
CVE-2018-16706 is a vulnerability in LG SuperSign CMS that allows TVs to be rebooted remotely without authentication.
2
How severe is CVE-2018-16706?
CVE-2018-16706 has a severity rating of 7.5 (high).
3
How does CVE-2018-16706 work?
CVE-2018-16706 allows an attacker to reboot LG SuperSign CMS-enabled TVs remotely without authentication by sending a direct HTTP request to /qsr_server/device/reboot on port 9080.
4
What software is affected by CVE-2018-16706?
LG SuperSign CMS (version not specified) is affected by CVE-2018-16706.
5
Is there a fix for CVE-2018-16706?
At the moment, there is no fix available for CVE-2018-16706. It is recommended to apply security measures like network segmentation or firewall rules to limit access to vulnerable TVs.