vendor:
SuperSignEZ
by:
Alejandro Fanjul
9.8
CVSS
CRITICAL
Remote Code Execution
78
CWE
Product Name: SuperSignEZ
Affected Version From: SuperSignEZ 1.3
Affected Version To: SuperSignEZ 1.3
Patch Exists: NO
Related CWE: CVE-2018-17173
CPE: LG/SuperSignEZ
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: LG WebOS 3.10
2018
LG SuperSign EZ CMS 2.5 – Remote Code Execution
LG SuperSignEZ CMS, that many LG SuperSign TVs have built in, is prone to remote code execution due to an improper parameter handling. Code to exploit the vulnerability is provided in the text.
Mitigation:
Ensure that proper parameter handling is implemented in the application.