peter bassill · operator
$ cve CVE-2018-16946 JSON

CVE-2018-16946 EXPLOIT

7.5
HIGH · CVSS 3.0 · EPSS 9.3% (pctl 95)

Patch early

A public exploit exists.

Description

LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /updownload/t.report (aka Log & Report) files and download backup files (via download.php) without authenticating. These backup files contain user credentials and configuration information for the camera device. An attacker is able to discover the backup filename via reading the system logs or report data, or just by brute-forcing the backup filename pattern. It may be possible to authenticate to the admin account with the admin password.

Scoring

CVSS7.5 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS9.35% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-552
On CISA KEVno
Public exploityes
Published2018-09-12
Last modified2026-06-17

Affected (36)

VendorProduct
lglnb5110
lglnb5110 firmware
lglnb5320
lglnb5320 firmware
lglnb5320r
lglnb5320r firmware
lglnb7210
lglnb7210 firmware
lglnd3230r
lglnd3230r firmware
lglnd5110
lglnd5110 firmware
lglnd5110r
lglnd5110r firmware
lglnd5220r
lglnd5220r firmware
lglnd7210
lglnd7210 firmware
lglnd7210r
lglnd7210r firmware
lglnu3230r
lglnu3230r firmware
lglnu5110r
lglnu5110r firmware
lglnu5320r
lglnu5320r firmware
lglnu7210r
lglnu7210r firmware
lglnv5110r
lglnv5110r firmware
lglnv5320r
lglnv5320r firmware
lglnv7210
lglnv7210 firmware
lglnv7210r
lglnv7210r firmware

Public exploits

SourceTitleDate
exploit-dbLG Smart IP Camera 1508190 - Backup File Download2018-09-12

References

→ the Explorer  ·  watch your stack  ·  NVD