First published: Fri Aug 25 2023(Updated: )
This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability.
Affected Software | Affected Version | How to fix |
---|---|---|
LG LED Assistant |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is ZDI-23-1221.
The severity level of ZDI-23-1221 is critical with a CVSS score of 9.8.
LG LED Assistant is affected by ZDI-23-1221.
No, authentication is not required to exploit ZDI-23-1221.
The specific flaw is a directory traversal remote code execution vulnerability in the /api/settings/upload endpoint of LG LED Assistant.