← Back

Lg

lg

66 CVEs • 159 products

Products (159)

Click to collapse
Toggle
Simple Editor
simple_editor
Supersign Cms
supersign_cms
Webos
webos
Webos Signage
webos_signage
Optimus G E973
optimus_g_e973
L 04d
l-04d
L 09c
l-09c
L 03e
l-03e
Lg Mobile
lg_mobile
Nexus 5
nexus_5
Lha.sys
lha.sys
N1a1 Firmware
n1a1_firmware
Pc Suite
pc_suite
Bridge
bridge
Ipsfullhd
ipsfullhd
Lg Ultrawide
lg_ultrawide
N1t1 Firmware
n1t1_firmware
Smart Share
smart_share
D806
d806
G5
g5
G6
g6
Q6
q6
Q8
q8
V10
v10
V20
v20
V30
v30
V30s Thinq
v30s_thinq
X Cam
x_cam
X300
x300
X400
x400
X500
x500
Lnb5110
lnb5110
Lnb5320
lnb5320
Lnb5320r
lnb5320r
Lnb7210
lnb7210
Lnd3230r
lnd3230r
Lnd5110
lnd5110
Lnd5110r
lnd5110r
Lnd5220r
lnd5220r
Lnd7210
lnd7210
Lnd7210r
lnd7210r
Lnu3230r
lnu3230r
Lnu5110r
lnu5110r
Lnu5320r
lnu5320r
Lnu7210r
lnu7210r
Lnv5110r
lnv5110r
Lnv5320r
lnv5320r
Lnv7210
lnv7210
Lnv7210r
lnv7210r
Gamp 7100
gamp-7100
Gapm 7200
gapm-7200
Gapm 8000
gapm-8000
N1a1
n1a1
E971
e971
E973
e973
E975
e975
E975k
e975k
E975t
e975t
E976
e976
E977
e977
F100k
f100k
F100l
f100l
F100s
f100s
F120k
f120k
F120l
f120l
F120s
f120s
F160k
f160k
F160l
f160l
F160lv
f160lv
F160s
f160s
F180k
f180k

CVEs (66)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lg
1Simple Editor
Apr 10, 2025
May 3, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
LG Simple Editor copyContent Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG Simple Editor. Authenticat...Show more
LG Simple Editor copyContent Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the copyContent command. The issue results from an exposed dangerous function. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. . Was ZDI-CAN-19945.Show less
1Lg
1Simple Editor
Apr 10, 2025
May 3, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
LG Simple Editor copyContent Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG Simple Editor. Authenticat...Show more
LG Simple Editor copyContent Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the copyContent command. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. . Was ZDI-CAN-19944.Show less
1Lg
1Simple Editor
Apr 10, 2025
May 3, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
LG Simple Editor mkdir Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of LG Simple Editor. Authentication is not...Show more
LG Simple Editor mkdir Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the mkdir command implemented in the makeDetailContent method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to delete files in the context of SYSTEM. . Was ZDI-CAN-19926.Show less
1Lg
1Simple Editor
Apr 10, 2025
May 3, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
LG Simple Editor cp Command Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG Simple Editor. Authentication is n...Show more
LG Simple Editor cp Command Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the cp command implemented in the makeDetailContent method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. . Was ZDI-CAN-19925.Show less
1Lg
1Simple Editor
Apr 10, 2025
May 3, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
LG Simple Editor saveXml Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG Simple Editor. Authentication is not...Show more
LG Simple Editor saveXml Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the saveXml command implemented in the makeDetailContent method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. . Was ZDI-CAN-19924.Show less
1Lg
1Simple Editor
Apr 10, 2025
May 3, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
LG Simple Editor copyStickerContent Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG Simple Editor. Au...Show more
LG Simple Editor copyStickerContent Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the copyStickerContent command. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM. . Was ZDI-CAN-19923.Show less
1Lg
1Simple Editor
Apr 4, 2025
May 3, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
LG Simple Editor copyTemplateAll Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG Simple Editor. Authe...Show more
LG Simple Editor copyTemplateAll Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the copyTemplateAll method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM. . Was ZDI-CAN-19922.Show less
1Lg
1Simple Editor
Apr 4, 2025
May 3, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
LG Simple Editor deleteFolder Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of LG Simple Editor. Authentication...Show more
LG Simple Editor deleteFolder Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the deleteFolder method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to delete files in the context of SYSTEM. . Was ZDI-CAN-19921.Show less
1Lg
1Simple Editor
Apr 4, 2025
May 3, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
LG Simple Editor copySessionFolder Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG Simple Editor. Authenticati...Show more
LG Simple Editor copySessionFolder Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the copySessionFolder command. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. . Was ZDI-CAN-19920.Show less
1Lg
1Simple Editor
Apr 23, 2025
May 3, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
LG Simple Editor deleteCheckSession Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of LG Simple Editor. Authentic...Show more
LG Simple Editor deleteCheckSession Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the deleteCheckSession method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to delete files in the context of SYSTEM. . Was ZDI-CAN-19919.Show less
1Lg
1Webos
Feb 7, 2025
Apr 9, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on webOS versions 5 and 6. A series of specially crafted requests can lead to command execution as the...Show more
A command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on webOS versions 5 and 6. A series of specially crafted requests can lead to command execution as the dbus user. An attacker can make authenticated requests to trigger this vulnerability. Full versions and TV models affected: * webOS 5.5.0 - 04.50.51 running on OLED55CXPUA  * webOS 6.3.3-442 (kisscurl-kinglake) - 03.36.50 running on OLED48C1PUB Show less
1Lg
1Webos
Feb 7, 2025
Apr 9, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A command injection vulnerability exists in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service on webOS version 4 through 7. A series of specially crafted requests can lead to command e...Show more
A command injection vulnerability exists in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service on webOS version 4 through 7. A series of specially crafted requests can lead to command execution as the root user. An attacker can make authenticated requests to trigger this vulnerability. * webOS 4.9.7 - 5.30.40 running on LG43UM7000PLA  * webOS 5.5.0 - 04.50.51 running on OLED55CXPUA  * webOS 6.3.3-442 (kisscurl-kinglake) - 03.36.50 running on OLED48C1PUB  * webOS 7.3.1-43 (mullet-mebin) - 03.33.85 running on OLED55A23LA Show less
1Lg
1Webos
Feb 7, 2025
Apr 9, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A command injection vulnerability exists in the processAnalyticsReport method from the com.webos.service.cloudupload service on webOS version 5 through 7. A series of specially crafted requests can lead to command execut...Show more
A command injection vulnerability exists in the processAnalyticsReport method from the com.webos.service.cloudupload service on webOS version 5 through 7. A series of specially crafted requests can lead to command execution as the root user. An attacker can make authenticated requests to trigger this vulnerability. Full versions and TV models affected: * webOS 5.5.0 - 04.50.51 running on OLED55CXPUA  * webOS 6.3.3-442 (kisscurl-kinglake) - 03.36.50 running on OLED48C1PUB  * webOS 7.3.1-43 (mullet-mebin) - 03.33.85 running on OLED55A23LA Show less
1Lg
1Webos
Feb 7, 2025
Apr 9, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without asking the user for the security PIN.  Full versions and TV models aff...Show more
A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without asking the user for the security PIN.  Full versions and TV models affected: webOS 4.9.7 - 5.30.40 running on LG43UM7000PLA webOS 5.5.0 - 04.50.51 running on OLED55CXPUA webOS 6.3.3-442 (kisscurl-kinglake) - 03.36.50 running on OLED48C1PUB   webOS 7.3.1-43 (mullet-mebin) - 03.33.85 running on OLED55A23LA Show less
1Lg
1Lg Led Assistant
Apr 4, 2025
Mar 25, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant.
1Lg
1Lg Led Assistant
Apr 1, 2025
Mar 25, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.
1Lg
1Webos Signage
Mar 3, 2025
Feb 26, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
This vulnerability allows remote attackers to traverse the directory on the affected webOS of LG Signage.
1Lg
1Webos Signage
Mar 3, 2025
Feb 26, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This vulnerability allows remote attackers to execute arbitrary code on the affected webOS of LG Signage.
1Lg
1Lg Led Assistant
Nov 21, 2024
Sep 4, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within th...Show more
This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/thumbnail endpoint. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of the current user.Show less
1Lg
1Lg Led Assistant
Nov 21, 2024
Sep 4, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within th...Show more
This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/download/updateFile endpoint. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of the current user.Show less