vendor:
LG NAS 3718.510.a0
by:
@0x616163
7.5
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: LG NAS 3718.510.a0
Affected Version From: 3718.510.a0
Affected Version To: 3718.510.a0
Patch Exists: YES
Related CWE: N/A
CPE: a:lg_electronics:lg_nas_3718.510.a0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
LG NAS 3718.510.a0 – Remote Command Execution
This vulnerability allows an attacker to execute arbitrary code on the target LG NAS device without authentication. This is achieved by sending a specially crafted POST request to the login_check.php page, which contains a malicious command in the password field. This command is then executed by the vulnerable code, allowing the attacker to gain remote access to the device.
Mitigation:
The vendor has released a patch to address this vulnerability.