First published: Fri Aug 25 2023(Updated: )
This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability.
Affected Software | Affected Version | How to fix |
---|---|---|
LG LED Assistant |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this LG LED Assistant vulnerability is ZDI-CAN-20210.
The title of this LG LED Assistant vulnerability is ZDI-23-1222: LG LED Assistant setThumbnailRc Directory Traversal Remote Code Execution Vulnerability.
The severity of the LG LED Assistant vulnerability is critical with a CVSS score of 9.8.
Remote attackers can exploit this LG LED Assistant vulnerability to execute arbitrary code on affected installations without authentication.
This LG LED Assistant vulnerability affects the /api/installation/setThumbnailRc endpoint.