LG's vulnerability footprint spans a moderately broad product portfolio centered on consumer and commercial display, television, and smart-device platforms including WebOS, the Q6 display line, and the SuperSign content-management system. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the internet-facing and operational-control role that many LG products occupy in retail, broadcast, and enterprise environments. The exposure recurs through weakness classes including path traversal, OS command injection, permission assignment flaws, and information disclosure, typical of embedded and firmware-based systems where input validation and access control boundaries are unevenly enforced. Defenders should prioritize inventory and network segmentation of internet-reachable LG devices and treat vendor advisories as high-urgency; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lg over time
Signals from CVEs in this vendor scope (87 CVEs).
87 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-14839CRITICAL LG N1A1 NAS 3718.510 is affected by: Remote Command Execution. The impact is: execute arbitrary code (remote). The attack vector is: HTTP POST with parameters. | May 14, 2019 | 9.8 | 95 | YES | NO |
CVE-2023-40504CRITICAL LG Simple Editor readVideoInfo Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations | May 3, 2024 | 9.8 | 87 | NO | YES |
CVE-2018-17173CRITICAL LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail. | Sep 21, 2018 | 9.8 | 81 | NO | YES |
CVE-2023-40498CRITICAL LG Simple Editor cp Command Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations | May 3, 2024 | 9.8 | 80 | NO | YES |
CVE-2024-2863CRITICAL This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant. | Mar 25, 2024 | 9.8 | 73 | NO | YES |
CVE-2023-40502CRITICAL LG Simple Editor cropImage Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations | May 3, 2024 | 9.1 | 72 | NO | NO |
CVE-2023-40494CRITICAL LG Simple Editor deleteFolder Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installati | May 3, 2024 | 9.1 | 70 | NO | NO |
CVE-2023-40492CRITICAL LG Simple Editor deleteCheckSession Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected inst | May 3, 2024 | 9.1 | 70 | NO | NO |
CVE-2024-2862CRITICAL
This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.
| Mar 25, 2024 | 9.8 | 70 | NO | YES |
CVE-2023-40497CRITICAL LG Simple Editor saveXml Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of | May 3, 2024 | 9.8 | 67 | NO | NO |
Signals from CVEs in this vendor scope (87 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lg.
Media articles that mention a CVE ID that affects a product developed by Lg — matched by CVE ID, not by vendor name.