Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Lg

First CVE: May 29, 2013Active for: 13 yearsTotal CVEs: 87
66.4
VTI Score
TOP TARGET

LG's vulnerability footprint spans a moderately broad product portfolio centered on consumer and commercial display, television, and smart-device platforms including WebOS, the Q6 display line, and the SuperSign content-management system. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the internet-facing and operational-control role that many LG products occupy in retail, broadcast, and enterprise environments. The exposure recurs through weakness classes including path traversal, OS command injection, permission assignment flaws, and information disclosure, typical of embedded and firmware-based systems where input validation and access control boundaries are unevenly enforced. Defenders should prioritize inventory and network segmentation of internet-reachable LG devices and treat vendor advisories as high-urgency; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
87
Total CVEs
More Total CVEs than 99% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.9
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
1.1%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Lg over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 29, 2013
13 years ago
Most Recent CVE
Jun 20, 2024
764 days ago

Products(159 total)

Top CVEs

Signals from CVEs in this vendor scope (87 CVEs).

87 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-14839CRITICAL
LG N1A1 NAS 3718.510 is affected by: Remote Command Execution. The impact is: execute arbitrary code (remote). The attack vector is: HTTP POST with parameters.
May 14, 20199.895YESNO
CVE-2023-40504CRITICAL
LG Simple Editor readVideoInfo Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations
May 3, 20249.887NOYES
CVE-2018-17173CRITICAL
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.
Sep 21, 20189.881NOYES
CVE-2023-40498CRITICAL
LG Simple Editor cp Command Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations
May 3, 20249.880NOYES
CVE-2024-2863CRITICAL
This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant.
Mar 25, 20249.873NOYES
CVE-2023-40502CRITICAL
LG Simple Editor cropImage Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations
May 3, 20249.172NONO
CVE-2023-40494CRITICAL
LG Simple Editor deleteFolder Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installati
May 3, 20249.170NONO
CVE-2023-40492CRITICAL
LG Simple Editor deleteCheckSession Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected inst
May 3, 20249.170NONO
CVE-2024-2862CRITICAL
This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.
Mar 25, 20249.870NOYES
CVE-2023-40497CRITICAL
LG Simple Editor saveXml Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of
May 3, 20249.867NONO
View all 87 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products87 CVEs
18%
40%
38%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local21 (24.1%)
Network62 (71.3%)
Unknown4 (4.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low78 (89.7%)
High5 (5.7%)
Unknown4 (4.6%)
User Interaction
None65 (74.7%)
Unknown4 (4.6%)
Required18 (20.7%)
Privileges Required
Low10 (11.5%)
High3 (3.4%)
None70 (80.5%)
Unknown4 (4.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (87 CVEs).

CISA KEV
1 CVE
1.1% of CVEs· 99th percentile
Metasploit
2 CVEs
2.3% of CVEs· 97th percentile
Nuclei
5 CVEs
5.7% of CVEs· 96th percentile
ExploitDB
4 CVEs
4.6% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Lg.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Lg — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Lg's Products

View all 6 CNAs →

Top CWEs