vendor:
DVR LE6016D
by:
Todor Donev
9.3
CVSS
HIGH
Unauthenticated Remote Access
287
CWE
Product Name: DVR LE6016D
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2015
LG DVR LE6016D unauthenticated remote users/passwords disclosure exploit
This program demonstrates how unpatched security bug would enable hackers to gain control of a vulnerable device while sitting behind their keyboard, potentially thousands of miles away. An unauthenticated attacker that is connected to the DVR's may be able to retrieve the device's administrator password allowing them to directly access the device's configuration control panel.
Mitigation:
Ensure that all devices are updated with the latest security patches and that access to the device is restricted to authorized personnel only.