Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-16946


LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /updownload/t.report (aka Log & Report) files and download backup files (via download.php) without authenticating. These backup files contain user credentials and configuration information for the camera device. An attacker is able to discover the backup filename via reading the system logs or report data, or just by brute-forcing the backup filename pattern. It may be possible to authenticate to the admin account with the admin password.


Published

2018-09-12T01:29:00.250

Last Modified

2024-11-21T03:53:33.647

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-552

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System lg lnb5110_firmware ≤ 1508190 Yes
Hardware lg lnb5110 - No
Operating System lg lnb5320_firmware ≤ 1508190 Yes
Hardware lg lnb5320 - No
Operating System lg lnb5320r_firmware ≤ 1508190 Yes
Hardware lg lnb5320r - No
Operating System lg lnb7210_firmware ≤ 1508190 Yes
Hardware lg lnb7210 - No
Operating System lg lnd3230r_firmware ≤ 1508190 Yes
Hardware lg lnd3230r - No
Operating System lg lnd5110_firmware ≤ 1508190 Yes
Hardware lg lnd5110 - No
Operating System lg lnd5110r_firmware ≤ 1508190 Yes
Hardware lg lnd5110r - No
Operating System lg lnd5220r_firmware ≤ 1508190 Yes
Hardware lg lnd5220r - No
Operating System lg lnd7210_firmware ≤ 1508190 Yes
Hardware lg lnd7210 - No
Operating System lg lnd7210r_firmware ≤ 1508190 Yes
Hardware lg lnd7210r - No
Operating System lg lnu3230r_firmware ≤ 1508190 Yes
Hardware lg lnu3230r - No
Operating System lg lnu5110r_firmware ≤ 1508190 Yes
Hardware lg lnu5110r - No
Operating System lg lnu5320r_firmware ≤ 1508190 Yes
Hardware lg lnu5320r - No
Operating System lg lnu7210r_firmware ≤ 1508190 Yes
Hardware lg lnu7210r - No
Operating System lg lnv5110r_firmware ≤ 1508190 Yes
Hardware lg lnv5110r - No
Operating System lg lnv5320r_firmware ≤ 1508190 Yes
Hardware lg lnv5320r - No
Operating System lg lnv7210_firmware ≤ 1508190 Yes
Hardware lg lnv7210 - No
Operating System lg lnv7210r_firmware ≤ 1508190 Yes
Hardware lg lnv7210r - No

References