By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Over 90,000 LG Smart TVs may be exposed to remote attacks
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Over 90,000 LG Smart TVs may be exposed to remote attacks
Tech News

Over 90,000 LG Smart TVs may be exposed to remote attacks

By admin 3 Min Read
Share
SHARE

Security researchers at Bitdefender have discovered four vulnerabilities impacting multiple versions of WebOS, the operating system used in LG smart TVs.

The flaws enable varying degrees of unauthorized access and control over affected models, including authorization bypasses, privilege escalation, and command injection.

The potential attacks hinge on the ability to create arbitrary accounts on the device using a service that runs on ports 3000/3001, which is available for smartphone connectivity, using a PIN.

PIN to connect to the TV
<strong>PIN to connect to the TV</strong> <em>(Bitdefender)</em>

Bitdefender explains that although the vulnerable LG WebOS service is supposed to be used only in local area networks (LAN) settings, Shodan internet scans show 91,000 exposed devices that are potentially vulnerable to the flaws.

Exposure of the vulnerable service
<strong>Exposure of the vulnerable service</strong> <em>(Bitdefender)</em>

The four flaws are summarized as follows:

  • CVE-2023-6317 allows attackers to bypass the TV’s authorization mechanism by exploiting a variable setting, enabling the addition of an extra user to the TV set without proper authorization.
  • CVE-2023-6318 is an elevation of privilege vulnerability that allows attackers to gain root access following the initial unauthorized access provided by CVE-2023-6317.
  • CVE-2023-6319 involves operating system command injection via manipulation of a library responsible for displaying music lyrics, allowing execution of arbitrary commands.
  • CVE-2023-6320 permits authenticated command injection by exploiting the com.webos.service.connectionmanager/tv/setVlanStaticAddress API endpoint, enabling command execution as the dbus user, which has similar permissions to the root user.

The vulnerabilities impact webOS 4.9.7 – 5.30.40 on LG43UM7000PLA, webOS 04.50.51 – 5.5.0 on OLED55CXPUA, webOS 0.36.50 – 6.3.3-442 on OLED48C1PUB, and webOS 03.33.85 – 7.3.1-43 on OLED55A23LA.

Bitdefender reported its findings to LG on November 1, 2023, but it took the vendor until March 22, 2024, to release the related security updates.

Though LG TVs alert users when important WebOS updates are available, those can be postponed indefinitely. Therefore, impacted users should apply the update by going to the TV’s Settings > Support > Software Update, and selecting “Check for Update.”

Applying WebOS updates automatically when available can be enabled from the same menu.

Though TVs are less critical in terms of security, the severity of remote command execution remains potentially significant in this case as it could give attackers a pivot point to reach other, more sensitive devices connected to the same network.

Moreover, smart TVs often have applications that require accounts, like streaming services, which the attacker could potentially steal to take control of those accounts.

Finally, vulnerable TVs can be compromised by malware botnets that enlist them in distributed denial of service (DDoS) attacks or used for cryptomining.

You Might Also Like

iMP Tech Mini Arcade Pro Review: A Nintendo Switch Arcade Cabinet

Defence and Security vulnerabilities critical issue for business – Ibec

Cisco Premier Provider Worldwide Status for Viatel Technology Group

Why Pet-Focused Air Purification Is Becoming a Smart-Home Essential

MongoDB Attacks, Wallet Breaches, Android Spyware, Insider Crime & More

TAGGED: Authentication Bypass, Command Injection, LG, TV, Vulnerability, WebOS
Share This Article
Facebook Twitter Copy Link
Previous Article Chargers RB Gus Edwards: I 'love' OC Greg Roman's scheme
Next Article Section 702: The Future of the Biggest US Spy Program Hangs in the Balance
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Denargo Market to open beer garden in 2026
Business
iMP Tech Mini Arcade Pro Review: A Nintendo Switch Arcade Cabinet
Tech News
Polkadot price forecast: market weakness hinders bulls near 1.90
Crypto
The hidden impact of domestic cats on wildlife revealed by social media
World News
Pundit Shares ‘Urgent Update’ With XRP Community – Here’s What He Said
Crypto
Gillingham fans have last laugh after being told to ‘sit down’ by Cambridge’s Pelly Ruddock Mpanzu
Sports
Defence and Security vulnerabilities critical issue for business – Ibec
Tech News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Denargo Market to open beer garden in 2026

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Denargo Market to open beer garden in 2026
December 29, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?