CVE-2018-16946: LG LNB5110 Firmware

High severity, CVSS 7.5. EPSS: 9.3% chance of exploitation in the next 30 days.

LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /updownload/t.report (aka Log & Report) files and download backup files (via download.php) without authenticating. These backup files contain user credentials and configuration information for the camera device. An attacker is able to discover the backup filename via reading the system logs or report data, or just by brute-forcing the backup filename pattern. It may be possible to authenticate to the admin account with the admin password.

Affected products

  • LG LNB5110 Firmware: from 1310250, up to and including 1508190
  • LG LNB5320 Firmware: from 1310250, up to and including 1508190
  • LG LNB5320R Firmware: from 1310250, up to and including 1508190
  • LG LNB7210 Firmware: from 1310250, up to and including 1508190
  • LG LND3230R Firmware: from 1310250, up to and including 1508190
  • LG LND5110 Firmware: from 1310250, up to and including 1508190
  • LG LND5110R Firmware: from 1310250, up to and including 1508190
  • LG LND5220R Firmware: from 1310250, up to and including 1508190
  • LG LND7210 Firmware: from 1310250, up to and including 1508190
  • LG LND7210R Firmware: from 1310250, up to and including 1508190
  • LG LNU3230R Firmware: from 1310250, up to and including 1508190
  • LG LNU5110R Firmware: from 1310250, up to and including 1508190
  • LG LNU5320R Firmware: from 1310250, up to and including 1508190
  • LG LNU7210R Firmware: from 1310250, up to and including 1508190
  • LG LNV5110R Firmware: from 1310250, up to and including 1508190
  • LG LNV5320R Firmware: from 1310250, up to and including 1508190
  • LG LNV7210 Firmware: from 1310250, up to and including 1508190
  • LG LNV7210R Firmware: from 1310250, up to and including 1508190

Published 2018-09-12. Last modified 2026-06-17.