CVE-2018-17173: LG Supersign CMS

Critical severity, CVSS 9.8. EPSS: 56.2% chance of exploitation in the next 30 days.

LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.

Affected products

  • LG Supersign CMS: version 2.5 only

Published 2018-09-21. Last modified 2026-06-17.