CVE-2018-16946
Summary
| CVE | CVE-2018-16946 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-09-12 01:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /updownload/t.report (aka Log & Report) files and download backup files (via download.php) without authenticating. These backup files contain user credentials and configuration information for the camera device. An attacker is able to discover the backup filename via reading the system logs or report data, or just by brute-forcing the backup filename pattern. It may be possible to authenticate to the admin account with the admin password. |
Risk And Classification
Problem Types: CWE-552
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Lg | Lnb5110 | - | All | All | All |
| Hardware | Lg | Lnb5110 | - | All | All | All |
| Operating System | Lg | Lnb5110 Firmware | All | All | All | All |
| Hardware | Lg | Lnb5320 | - | All | All | All |
| Hardware | Lg | Lnb5320 | - | All | All | All |
| Hardware | Lg | Lnb5320r | - | All | All | All |
| Hardware | Lg | Lnb5320r | - | All | All | All |
| Operating System | Lg | Lnb5320r Firmware | All | All | All | All |
| Operating System | Lg | Lnb5320 Firmware | All | All | All | All |
| Hardware | Lg | Lnb7210 | - | All | All | All |
| Hardware | Lg | Lnb7210 | - | All | All | All |
| Operating System | Lg | Lnb7210 Firmware | All | All | All | All |
| Hardware | Lg | Lnd3230r | - | All | All | All |
| Hardware | Lg | Lnd3230r | - | All | All | All |
| Operating System | Lg | Lnd3230r Firmware | All | All | All | All |
| Hardware | Lg | Lnd5110 | - | All | All | All |
| Hardware | Lg | Lnd5110 | - | All | All | All |
| Hardware | Lg | Lnd5110r | - | All | All | All |
| Hardware | Lg | Lnd5110r | - | All | All | All |
| Operating System | Lg | Lnd5110r Firmware | All | All | All | All |
| Operating System | Lg | Lnd5110 Firmware | All | All | All | All |
| Hardware | Lg | Lnd5220r | - | All | All | All |
| Hardware | Lg | Lnd5220r | - | All | All | All |
| Operating System | Lg | Lnd5220r Firmware | All | All | All | All |
| Hardware | Lg | Lnd7210 | - | All | All | All |
| Hardware | Lg | Lnd7210 | - | All | All | All |
| Hardware | Lg | Lnd7210r | - | All | All | All |
| Hardware | Lg | Lnd7210r | - | All | All | All |
| Operating System | Lg | Lnd7210r Firmware | All | All | All | All |
| Operating System | Lg | Lnd7210 Firmware | All | All | All | All |
| Hardware | Lg | Lnu3230r | - | All | All | All |
| Hardware | Lg | Lnu3230r | - | All | All | All |
| Operating System | Lg | Lnu3230r Firmware | All | All | All | All |
| Hardware | Lg | Lnu5110r | - | All | All | All |
| Hardware | Lg | Lnu5110r | - | All | All | All |
| Operating System | Lg | Lnu5110r Firmware | All | All | All | All |
| Hardware | Lg | Lnu5320r | - | All | All | All |
| Hardware | Lg | Lnu5320r | - | All | All | All |
| Operating System | Lg | Lnu5320r Firmware | All | All | All | All |
| Hardware | Lg | Lnu7210r | - | All | All | All |
| Hardware | Lg | Lnu7210r | - | All | All | All |
| Operating System | Lg | Lnu7210r Firmware | All | All | All | All |
| Hardware | Lg | Lnv5110r | - | All | All | All |
| Hardware | Lg | Lnv5110r | - | All | All | All |
| Operating System | Lg | Lnv5110r Firmware | All | All | All | All |
| Hardware | Lg | Lnv5320r | - | All | All | All |
| Hardware | Lg | Lnv5320r | - | All | All | All |
| Operating System | Lg | Lnv5320r Firmware | All | All | All | All |
| Hardware | Lg | Lnv7210 | - | All | All | All |
| Hardware | Lg | Lnv7210 | - | All | All | All |
| Hardware | Lg | Lnv7210r | - | All | All | All |
| Hardware | Lg | Lnv7210r | - | All | All | All |
| Operating System | Lg | Lnv7210r Firmware | All | All | All | All |
| Operating System | Lg | Lnv7210 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| LG Smart IP Camera 1508190 - Backup File Download - Hardware webapps Exploit | EXPLOIT-DB | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| GitHub - EgeBalci/LG-Smart-IP-Device-Backup-Download: Exploit for downloading backup files from LG Smart IP Devices. | MISC | github.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.