VYPR
Unrated severityNVD Advisory· Published Apr 9, 2024· Updated Aug 2, 2024

PIN/prompt bypass on the secondscreen.gateway service allows access to the SSAP API without user interaction

CVE-2023-6317

Description

A prompt bypass in secondscreen.gateway on webOS 4-7 allows attackers to create a privileged account without the security PIN.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A prompt bypass in secondscreen.gateway on webOS 4-7 allows attackers to create a privileged account without the security PIN.

Vulnerability

The secondscreen.gateway service on webOS versions 4 through 7 contains a prompt bypass vulnerability. By setting a specific variable, an attacker can add a new user without providing the security PIN. Affected versions include webOS 4.9.7 - 5.30.40 (LG43UM7000PLA), webOS 5.5.0 - 04.50.51 (OLED55CXPUA), webOS 6.3.3-442 - 03.36.50 (OLED48C1PUB), and webOS 7.3.1-43 - 03.33.85 (OLED55A23LA) [1].

Exploitation

An attacker with network access to the vulnerable service (typically on ports 3000/3001) can send a crafted request that sets a variable to bypass the PIN prompt, thereby creating a privileged account. The service is intended for LAN access but over 91,000 devices were found exposed on the Internet via Shodan [1]. No user interaction is required.

Impact

Successful exploitation allows the attacker to create a privileged account on the TV, bypassing the standard PIN-based authentication. This account can then be used to further compromise the device, such as exploiting CVE-2023-6318 to gain root access and full control [1].

Mitigation

LG released a patch on March 22, 2024. Users should update their TV firmware to the latest version provided by the manufacturer. No workarounds are available. This vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • LG/webOSllm-fuzzy2 versions
    4.0 - 7.3.1-43+ 1 more
    • (no CPE)range: 4.0 - 7.3.1-43
    • (no CPE)range: 4.9.7

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.