Description
A command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on webOS versions 5 and 6. A series of specially crafted requests can lead to command execution as the dbus user. An attacker can make authenticated requests to trigger this vulnerability.
Full versions and TV models affected:
* webOS 5.5.0 - 04.50.51 running on OLED55CXPUA
* webOS 6.3.3-442 (kisscurl-kinglake) - 03.36.50 running on OLED48C1PUB
Full versions and TV models affected:
* webOS 5.5.0 - 04.50.51 running on OLED55CXPUA
* webOS 6.3.3-442 (kisscurl-kinglake) - 03.36.50 running on OLED48C1PUB
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-58562 | A command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on webOS versions 5 and 6. A series of specially crafted requests can lead to command execution as the dbus user. An attacker can make authenticated requests to trigger this vulnerability. Full versions and TV models affected: * webOS 5.5.0 - 04.50.51 running on OLED55CXPUA * webOS 6.3.3-442 (kisscurl-kinglake) - 03.36.50 running on OLED48C1PUB |
References
History
Fri, 07 Feb 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lg
Lg oled48c1pub Lg oled55cxpua Lg webos |
|
| CPEs | cpe:2.3:h:lg:oled48c1pub:-:*:*:*:*:*:*:* cpe:2.3:h:lg:oled55cxpua:-:*:*:*:*:*:*:* cpe:2.3:o:lg:webos:5.5.0:*:*:*:*:*:*:* cpe:2.3:o:lg:webos:6.3.3-442:*:*:*:*:*:*:* |
|
| Vendors & Products |
Lg
Lg oled48c1pub Lg oled55cxpua Lg webos |
Status: PUBLISHED
Assigner: Bitdefender
Published:
Updated: 2024-08-02T08:28:21.166Z
Reserved: 2023-11-27T14:22:32.470Z
Link: CVE-2023-6320
Updated: 2024-08-02T08:28:21.166Z
Status : Analyzed
Published: 2024-04-09T14:15:08.287
Modified: 2025-02-07T18:15:18.370
Link: CVE-2023-6320
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD