• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
researchers discover lg smart tv vulnerabilities allowing root access

Researchers Discover LG Smart TV Vulnerabilities Allowing Root Access

You are here: Home / General Cyber Security News / Researchers Discover LG Smart TV Vulnerabilities Allowing Root Access
April 9, 2024

Many security vulnerabilities have been disclosed in LG webOS jogging on its sensible televisions that could be exploited to bypass authorization and achieve root obtain on the units.

The findings come from Romanian cybersecurity business Bitdefender, which identified and described the flaws in November 2023. The issues were set by LG as part of updates released on March 22, 2024.

The vulnerabilities are tracked from CVE-2023-6317 by way of CVE-2023-6320 and effect the adhering to variations of webOS –

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


  • webOS 4.9.7 – 5.30.40 managing on LG43UM7000PLA
  • webOS 5.5. – 04.50.51 functioning on OLED55CXPUA
  • webOS 6.3.3-442 (kisscurl-kinglake) – 03.36.50 functioning on OLED48C1PUB
  • webOS 7.3.1-43 (mullet-mebin) – 03.33.85 working on OLED55A23LA

Cybersecurity

A transient description of the shortcomings is as follows –

  • CVE-2023-6317 – A vulnerability that permits an attacker to bypass PIN verification and insert a privileged person profile to the Tv set established with out demanding user interaction
  • CVE-2023-6318 – A vulnerability that makes it possible for the attacker to elevate their privileges and attain root entry to get handle of the system
  • CVE-2023-6319 – A vulnerability that enables running program command injection by manipulating a library named asm responsible for showing music lyrics
  • CVE-2023-6320 – A vulnerability that allows for the injection of authenticated instructions by manipulating the com.webos.service.connectionmanager/television/setVlanStaticAddress API endpoint

Effective exploitation of the flaws could permit a danger actor to obtain elevated permissions to the product, which, in flip, can be chained with CVE-2023-6318 and CVE-2023-6319 to get hold of root accessibility, or with CVE-2023-6320 to operate arbitrary instructions as the dbus user.

LG Smart TV Vulnerabilities

“Despite the fact that the susceptible company is supposed for LAN obtain only, Shodan, the research motor for Internet-related gadgets, identified above 91,000 equipment that expose this company to the Internet,” Bitdefender mentioned. A bulk of the equipment are situated in South Korea, Hong Kong, the U.S., Sweden, Finland, and Latvia.

Uncovered this post attention-grabbing? Observe us on Twitter  and LinkedIn to browse much more special material we put up.


Some parts of this short article are sourced from:
thehackernews.com

Previous Post: «cl0p's ransomware rampage security measures for 2024 CL0P’s Ransomware Rampage – Security Measures for 2024
Next Post: Hackers Targeting Human Rights Activists in Morocco and Western Sahara hackers targeting human rights activists in morocco and western sahara»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • New HTTPBot Botnet Launches 200+ Precision DDoS Attacks on Gaming and Tech Sectors
  • Top 10 Best Practices for Effective Data Protection
  • Researchers Expose New Intel CPU Flaws Enabling Memory Leaks and Spectre v2 Attacks
  • Fileless Remcos RAT Delivered via LNK Files and MSHTA in PowerShell-Based Attacks
  • [Webinar] From Code to Cloud to SOC: Learn a Smarter Way to Defend Modern Applications
  • Meta to Train AI on E.U. User Data From May 27 Without Consent; Noyb Threatens Lawsuit
  • Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt Fails
  • Pen Testing for Compliance Only? It’s Time to Change Your Approach
  • 5 BCDR Essentials for Effective Ransomware Defense
  • Russia-Linked APT28 Exploited MDaemon Zero-Day to Hack Government Webmail Servers

Copyright © TheCyberSecurity.News, All Rights Reserved.