CVE-2023-6320

A command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on webOS versions 5 and 6. A series of specially crafted requests can lead to command execution as the dbus user. An attacker can make authenticated requests to trigger this vulnerability. Full versions and TV models affected: * webOS 5.5.0 - 04.50.51 running on OLED55CXPUA  * webOS 6.3.3-442 (kisscurl-kinglake) - 03.36.50 running on OLED48C1PUB
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:lg:webos:5.5.0:*:*:*:*:*:*:*
cpe:2.3:h:lg:oled55cxpua:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:lg:webos:6.3.3-442:*:*:*:*:*:*:*
cpe:2.3:h:lg:oled48c1pub:-:*:*:*:*:*:*:*

History

07 Feb 2025, 18:15

Type Values Removed Values Added
CPE cpe:2.3:h:lg:oled48c1pub:-:*:*:*:*:*:*:*
cpe:2.3:o:lg:webos:5.5.0:*:*:*:*:*:*:*
cpe:2.3:h:lg:oled55cxpua:-:*:*:*:*:*:*:*
cpe:2.3:o:lg:webos:6.3.3-442:*:*:*:*:*:*:*
References () https://bitdefender.com/blog/labs/vulnerabilities-identified-in-lg-webos/ - () https://bitdefender.com/blog/labs/vulnerabilities-identified-in-lg-webos/ - Exploit, Third Party Advisory
References () https://lgsecurity.lge.com/bulletins/tv#updateDetails - () https://lgsecurity.lge.com/bulletins/tv#updateDetails - Vendor Advisory
First Time Lg webos
Lg
Lg oled48c1pub
Lg oled55cxpua

Information

Published : 2024-04-09 14:15

Updated : 2025-02-07 18:15


NVD link : CVE-2023-6320

Mitre link : CVE-2023-6320

CVE.ORG link : CVE-2023-6320


JSON object : View

Products Affected

lg

  • oled48c1pub
  • oled55cxpua
  • webos
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')