CVE Feed

    Dashboard / CVE / CVE-2018-16946

    CVE-2018-16946

    LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /updownload/t.report (aka Log & Report) files and download backup files (via download.php) without authenticating. These backup files contain user credentials and configuration information for the camera device. An attacker is able to discover the backup filename via reading the system logs or report data, or just by brute-forcing the backup filename pattern. It may be possible to authenticate to the admin account with the admin password.

    Published:Sep 12, 2018
    Last Modified:Nov 21, 2024
    EPS:Sep 12, 2018
    EPSS Score:0.11515
    CVSS Score:7.5

    Affected Products

    Vendor
    Lg
    Product
    Lnb5110
    Vendor
    Lg
    Product
    Lnb5110 Firmware
    Vendor
    Lg
    Product
    Lnb5320
    Vendor
    Lg
    Product
    Lnb5320 Firmware
    Vendor
    Lg
    Product
    Lnb5320r
    Vendor
    Lg
    Product
    Lnb5320r Firmware
    Vendor
    Lg
    Product
    Lnb7210
    Vendor
    Lg
    Product
    Lnb7210 Firmware
    Vendor
    Lg
    Product
    Lnd3230r
    Vendor
    Lg
    Product
    Lnd3230r Firmware
    Vendor
    Lg
    Product
    Lnd5110
    Vendor
    Lg
    Product
    Lnd5110 Firmware
    Vendor
    Lg
    Product
    Lnd5110r
    Vendor
    Lg
    Product
    Lnd5110r Firmware
    Vendor
    Lg
    Product
    Lnd5220r
    Vendor
    Lg
    Product
    Lnd5220r Firmware
    Vendor
    Lg
    Product
    Lnd7210
    Vendor
    Lg
    Product
    Lnd7210 Firmware
    Vendor
    Lg
    Product
    Lnd7210r
    Vendor
    Lg
    Product
    Lnd7210r Firmware
    Vendor
    Lg
    Product
    Lnu3230r
    Vendor
    Lg
    Product
    Lnu3230r Firmware
    Vendor
    Lg
    Product
    Lnu5110r
    Vendor
    Lg
    Product
    Lnu5110r Firmware
    Vendor
    Lg
    Product
    Lnu5320r
    Vendor
    Lg
    Product
    Lnu5320r Firmware
    Vendor
    Lg
    Product
    Lnu7210r
    Vendor
    Lg
    Product
    Lnu7210r Firmware
    Vendor
    Lg
    Product
    Lnv5110r
    Vendor
    Lg
    Product
    Lnv5110r Firmware
    Vendor
    Lg
    Product
    Lnv5320r
    Vendor
    Lg
    Product
    Lnv5320r Firmware
    Vendor
    Lg
    Product
    Lnv7210
    Vendor
    Lg
    Product
    Lnv7210 Firmware
    Vendor
    Lg
    Product
    Lnv7210r
    Vendor
    Lg
    Product
    Lnv7210r Firmware

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High