Vulnerability record · CVE-2018-17173 · published 21 September 2018
CVE-2018-17173: LG SuperSign CMS code injection in getThumbnail sourceUri parameter
Lg · Supersign Cms
LG SuperSign CMS is vulnerable to code injection (CWE-94) through the sourceUri parameter passed to qsr_server/device/getThumbnail. A remote, unauthenticated attacker can supply crafted input that leads to arbitrary code execution on the server. The flaw is rated critical (CVSS 3.0 9.8) and public exploit code exists, making it a serious risk for exposed CMS instances.
Description
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, public exploit code available, and a very high EPSS score make this an urgent risk for any exposed LG SuperSign CMS instance.
What it is
LG SuperSign CMS is vulnerable to code injection (CWE-94) through the sourceUri parameter passed to qsr_server/device/getThumbnail. A remote, unauthenticated attacker can supply crafted input that leads to arbitrary code execution on the server. The flaw is rated critical (CVSS 3.0 9.8) and public exploit code exists, making it a serious risk for exposed CMS instances.
Impact
Successful exploitation gives the attacker arbitrary code execution with the privileges of the CMS service, allowing full compromise of the host. This can lead to data theft, lateral movement, or use of the system as a foothold in the network.
Attack surface
The vulnerability is reachable over the network via the qsr_server/device/getThumbnail endpoint, specifically through the sourceUri parameter. The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.
Exploitation
Public exploit code is available (Exploit-DB entries 45448 and 46795, plus Packet Storm and a technical blog post), and EPSS is high at 0.56237 (99th percentile). The CVE is not listed in CISA KEV, so there is no confirmed in-the-wild exploitation record in that dataset.
What to do
- Apply the vendor patch or upgrade to a fixed version of LG SuperSign CMS as soon as possible.
- Restrict network access to the qsr_server/device/getThumbnail endpoint and the CMS management interface to trusted networks only.
- If patching is not immediately possible, deploy a WAF rule or input validation to block malicious sourceUri values.
- Monitor and audit CMS server logs for unusual requests to getThumbnail or signs of post-exploitation activity.
- Isolate the CMS server from other critical systems to limit lateral movement in case of compromise.
Detection
- Search web server and application logs for requests to qsr_server/device/getThumbnail with suspicious or malformed sourceUri parameters.
- Monitor for unexpected child processes or command execution spawned by the CMS service account.
- Use network monitoring to detect outbound connections from the CMS server to unknown or untrusted hosts.
- Check for known exploit payload patterns or indicators from the public Exploit-DB entries in HTTP traffic.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://mamaquieroserpentester.blogspot.com/2018/09/lg-supersign-rce-to-luna-and-back-to.html | ExploitTechnical DescriptionThird Party Advisory |
| http://packetstormsecurity.com/files/152733/LG-Supersign-EZ-CMS-Remote-Code-Execution.html | |
| https://www.exploit-db.com/exploits/45448/ | Third Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/46795/ | |
| http://mamaquieroserpentester.blogspot.com/2018/09/lg-supersign-rce-to-luna-and-back-to.html | ExploitTechnical DescriptionThird Party Advisory |
| http://packetstormsecurity.com/files/152733/LG-Supersign-EZ-CMS-Remote-Code-Execution.html | |
| https://www.exploit-db.com/exploits/45448/ | Third Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/46795/ |
Track CVE-2018-17173 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-17173), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.