← Back

CVE-2018-16946

nvd nist
Published: Sep 12, 2018Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /updownload/t.report (aka Log & Report) files and download backup files (via download.php) without authenticating. These backup files contain user credentials and configuration information for the camera device. An attacker is able to discover the backup filename via reading the system logs or report data, or just by brute-forcing the backup filename pattern. It may be possible to authenticate to the admin account with the admin password.

Affected (18)

18 products
Lnb5110 Firmware
Lnb5320 Firmware
Lnb5320r Firmware
Lnb7210 Firmware
Lnd3230r Firmware
Lnd5110 Firmware
Lnd5110r Firmware
Lnd5220r Firmware
Lnd7210 Firmware
Lnd7210r Firmware
Lnu3230r Firmware
Lnu5110r Firmware
Lnu5320r Firmware
Lnu7210r Firmware
Lnv5110r Firmware
Lnv5320r Firmware
Lnv7210 Firmware
Lnv7210r Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 1310250 to 1508190
Running on/withPlatform Versions
Lg
Lnb5110
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 1310250 to 1508190
Running on/withPlatform Versions
Lg
Lnb5320
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 1310250 to 1508190
Running on/withPlatform Versions
Lg
Lnb5320r
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 1310250 to 1508190
Running on/withPlatform Versions
Lg
Lnb7210
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 1310250 to 1508190
Running on/withPlatform Versions
Lg
Lnd3230r
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 1310250 to 1508190
Running on/withPlatform Versions
Lg
Lnd5110
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 1310250 to 1508190
Running on/withPlatform Versions
Lg
Lnd5110r
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 1310250 to 1508190
Running on/withPlatform Versions
Lg
Lnd5220r
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 1310250 to 1508190
Running on/withPlatform Versions
Lg
Lnd7210
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 1310250 to 1508190
Running on/withPlatform Versions
Lg
Lnd7210r
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 1310250 to 1508190
Running on/withPlatform Versions
Lg
Lnu3230r
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 1310250 to 1508190
Running on/withPlatform Versions
Lg
Lnu5110r
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 1310250 to 1508190
Running on/withPlatform Versions
Lg
Lnu5320r
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 1310250 to 1508190
Running on/withPlatform Versions
Lg
Lnu7210r
All versions
Configuration O
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 1310250 to 1508190
Running on/withPlatform Versions
Lg
Lnv5110r
All versions
Configuration P
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 1310250 to 1508190
Running on/withPlatform Versions
Lg
Lnv5320r
All versions
Configuration Q
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 1310250 to 1508190
Running on/withPlatform Versions
Lg
Lnv7210
All versions
Configuration R
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 1310250 to 1508190
Running on/withPlatform Versions
Lg
Lnv7210r
All versions

References (4)

Source: cve@mitre.org
ExploitThird Party Advisory
Source: cve@mitre.org
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry

Timeline

No history available yet.