Command injection in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint
Description
Command injection in LG webOS connection manager service allows authenticated command execution as dbus user on webOS 5 and 6.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Command injection in LG webOS connection manager service allows authenticated command execution as dbus user on webOS 5 and 6.
Vulnerability
A command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on webOS versions 5 and 6. The affected versions are webOS 5.5.0 - 04.50.51 running on OLED55CXPUA and webOS 6.3.3-442 (kisscurl-kinglake) - 03.36.50 running on OLED48C1PUB [1]. The vulnerability allows an attacker with authenticated access to inject arbitrary commands.
Exploitation
An attacker must have authenticated access to the webOS device to trigger the vulnerability. By sending a series of specially crafted requests to the vulnerable endpoint, the attacker can inject operating system commands [1]. The specific steps involve manipulating the API input to execute commands as the dbus user.
Impact
Successful exploitation leads to command execution as the dbus user. Depending on further privileges, this could allow an attacker to gain root access, install malware, or access sensitive data on the device [1]. The scope of compromise is the TV set itself.
Mitigation
A patch was released by LG on March 22, 2024, as part of a firmware update [1]. Users should update their TV's firmware to the latest version available from LG's support website. No workaround is provided; updating is the only mitigation.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
2- lgsecurity.lge.com/bulletins/tvmitrevendor-advisory
- bitdefender.com/blog/labs/vulnerabilities-identified-in-lg-webos/mitre
News mentions
0No linked articles in our index yet.