CVE-2018-16946

UnknownEPSS 9.35%

Last modified

CVE-2018-16946 is a vulnerability of currently unknown severity. LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /updownload/t.report (aka Log & Report) files and download backup files (via download.php) without authenticating. EPSS estimates a 9.35% chance of exploitation in the next 30 days.

Description

LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /updownload/t.report (aka Log & Report) files and download backup files (via download.php) without authenticating. These backup files contain user credentials and configuration information for the camera device. An attacker is able to discover the backup filename via reading the system logs or report data, or just by brute-forcing the backup filename pattern. It may be possible to authenticate to the admin account with the admin password.

Metrics

EPSS Probability
9.35%

94.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LgLnb5110 Firmware>= 1310250, <= 1508190
LgLnb5320 Firmware>= 1310250, <= 1508190
LgLnb5320r Firmware>= 1310250, <= 1508190
LgLnb7210 Firmware>= 1310250, <= 1508190
LgLnd3230r Firmware>= 1310250, <= 1508190
LgLnd5110 Firmware>= 1310250, <= 1508190
LgLnd5110r Firmware>= 1310250, <= 1508190
LgLnd5220r Firmware>= 1310250, <= 1508190
LgLnd7210 Firmware>= 1310250, <= 1508190
LgLnd7210r Firmware>= 1310250, <= 1508190
LgLnu3230r Firmware>= 1310250, <= 1508190
LgLnu5110r Firmware>= 1310250, <= 1508190
LgLnu5320r Firmware>= 1310250, <= 1508190
LgLnu7210r Firmware>= 1310250, <= 1508190
LgLnv5110r Firmware>= 1310250, <= 1508190
LgLnv5320r Firmware>= 1310250, <= 1508190
LgLnv7210 Firmware>= 1310250, <= 1508190
LgLnv7210r Firmware>= 1310250, <= 1508190

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-16946?
LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /updownload/t.report (aka Log & Report) files and download backup files (via download.php) without authenticating. These backup files contain user credentials and configuration information for the camera device. An attacker is able to discover the backup filename via reading the system logs or report data, or just by brute-forcing the backup filename pattern. It may be possible to authenticate to the admin account with the admin password.
How severe is CVE-2018-16946?
Severity scoring for CVE-2018-16946 is pending analysis. The EPSS model estimates a 9.35% probability of exploitation in the next 30 days.
How do I fix CVE-2018-16946?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-16946?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST