漏洞描述 LG LED Assistant 是设置 LG LED灯光最简单、最方便的软件。LG LED get3DLutFile存在任意文件删除漏洞,此漏洞是由于get3DLutFile对请求中的参数数据验证不足导致的。
相关漏洞推荐 POC CVE-2024-2862: LG LED Assistant - Unauthenticated Password Reset POC CVE-2024-2863: LG LED Assistant - Thumbnail Path Traversal File Upload LG LED remove3DLUT 任意文件删除漏洞 LG LED Assistant智能灯管助手 CVE-2023-4614 远程代码执行漏洞 LG LED Assistant seamCorrectionFileCreate 目录遍历漏洞 LG LED Assistant thumbnail 目录遍历漏洞 LG LED Assistant upload 目录遍历漏洞 LG LED Assistant updateFile 目录遍历漏洞