CVE-2025-7742 is an authentication vulnerability in LG Innotek LNV5110R camera firmware, allowing an unauthenticated attacker to upload an HTTP POST request to non-volatile storage. This can lead to remote code execution with administrator privileges, enabling arbitrary command execution on the device. With a CVSS score of 8.3 (HIGH), the vulnerability is network-exploitable with low attack complexity, potentially impacting confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code, the vulnerability has garnered community discussion and media coverage, indicating awareness of the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| LG Innotek | Camera Model LNV5110R | AllCNA affecteddefault affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.