← Vulnerability feed

Vulnerability record · CVE-2018-17173 · published 21 September 2018

CVE-2018-17173: LG SuperSign CMS code injection in getThumbnail sourceUri parameter

Lg · Supersign Cms

LG SuperSign CMS is vulnerable to code injection (CWE-94) through the sourceUri parameter passed to qsr_server/device/getThumbnail. A remote, unauthenticated attacker can supply crafted input that leads to arbitrary code execution on the server. The flaw is rated critical (CVSS 3.0 9.8) and public exploit code exists, making it a serious risk for exposed CMS instances.

9.8 CVSS 3.0 Critical EPSS 56% · top 1.0% CWE-94 · Code injection
9.8CVSS 3.0 base score, v2 7.5
56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required, public exploit code available, and a very high EPSS score make this an urgent risk for any exposed LG SuperSign CMS instance.

What it is

LG SuperSign CMS is vulnerable to code injection (CWE-94) through the sourceUri parameter passed to qsr_server/device/getThumbnail. A remote, unauthenticated attacker can supply crafted input that leads to arbitrary code execution on the server. The flaw is rated critical (CVSS 3.0 9.8) and public exploit code exists, making it a serious risk for exposed CMS instances.

Impact

Successful exploitation gives the attacker arbitrary code execution with the privileges of the CMS service, allowing full compromise of the host. This can lead to data theft, lateral movement, or use of the system as a foothold in the network.

Attack surface

The vulnerability is reachable over the network via the qsr_server/device/getThumbnail endpoint, specifically through the sourceUri parameter. The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.

Exploitation

Public exploit code is available (Exploit-DB entries 45448 and 46795, plus Packet Storm and a technical blog post), and EPSS is high at 0.56237 (99th percentile). The CVE is not listed in CISA KEV, so there is no confirmed in-the-wild exploitation record in that dataset.

What to do

  • Apply the vendor patch or upgrade to a fixed version of LG SuperSign CMS as soon as possible.
  • Restrict network access to the qsr_server/device/getThumbnail endpoint and the CMS management interface to trusted networks only.
  • If patching is not immediately possible, deploy a WAF rule or input validation to block malicious sourceUri values.
  • Monitor and audit CMS server logs for unusual requests to getThumbnail or signs of post-exploitation activity.
  • Isolate the CMS server from other critical systems to limit lateral movement in case of compromise.

Detection

  • Search web server and application logs for requests to qsr_server/device/getThumbnail with suspicious or malformed sourceUri parameters.
  • Monitor for unexpected child processes or command execution spawned by the CMS service account.
  • Use network monitoring to detect outbound connections from the CMS server to unknown or untrusted hosts.
  • Check for known exploit payload patterns or indicators from the public Exploit-DB entries in HTTP traffic.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-17173 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-16287Lg supersign cms unrestricted file upload vulnerabilityLG SuperSign CMS allows file upload via signEzUI/playlist/edit/upload/..%2f URIs.EPSS 20%9.8CVE-2018-16286Lg supersign cms improper authentication vulnerabilityLG SuperSign CMS allows authentication bypass because the CAPTCHA requirement is skipped if a captcha:pass cookie is sent, and because the PIN is lim…EPSS 22%8.6CVE-2018-16288Lg supersign cms information exposure vulnerabilityLG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs.EPSS 36%7.5CVE-2018-16706Lg supersign cms vulnerabilityLG SuperSign CMS allows TVs to be rebooted remotely without authentication via a direct HTTP request to /qsr_server/device/reboot on port 9080.EPSS 22%4.8CVE-2024-6178Lg supersign cms cross-site scripting vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected X…EPSS 0.25%4.8CVE-2024-6179Lg supersign cms cross-site scripting vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected X…EPSS 0.25%4.8CVE-2024-6177Lg supersign cms cross-site scripting vulnerabilityImproper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Refl…EPSS 0.25%8.8CVE-2026-65660Microsoft sharepoint server code injection vulnerabilityImproper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.KEVEPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2018-17173), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.