CVE-2018-14839

CRITICAL KEV

LG N1A1 Firmware 3718.510 - Unauthenticated Remote Command Execution via HTTP POST Parameters

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2018-14839 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 25, 2022.

Description

LG N1A1 NAS 3718.510 is affected by: Remote Command Execution. The impact is: execute arbitrary code (remote). The attack vector is: HTTP POST with parameters.

Scores

CVSS v3 9.8
EPSS 0.8930
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2022-03-25
VulnCheck KEV 2022-03-25
InTheWild.io 2022-03-25
ENISA EUVD EUVD-2018-6722
CWE
CWE-78
Status published
Products (1)
lg/n1a1_firmware 3718.510
Published May 14, 2019
KEV Added Mar 25, 2022
Tracked Since Feb 18, 2026