Junglewise Threat Intelligence

CVE-2018-14839: LG N1A1 NAS Remote Command Execution Vulnerability

CVE-2018-14839 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-25

Executive brief

LG N1A1 NAS devices running firmware version 3718.510 are vulnerable to unauthenticated remote command injection. An attacker can execute arbitrary OS commands via a crafted HTTP POST request with specific parameters.

Affected products

  • LG N1A1 NAS 3718.510

Timeline

  • 2019-05-14: disclosed: NVD Published Date
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-25: exploited: Confirmed as exploited in the wild by CISA