← Vulnerability feed

Vulnerability record · CVE-2020-9759 · published 23 March 2020

CVE-2020-9759: Lg webos download of code without integrity check vulnerability

Lg · Webos

A Vulnerability of LG Electronic web OS TV Emulator could allow an attacker to escalate privileges and overwrite certain files. This vulnerability is due to wrong environment setting. An attacker could exploit this vulnerability through crafted configuration files and executable files.

7.8 CVSS 3.1 High EPSS 0.48% · top 61.1% CWE-494 · Download of code without integrity check
7.8CVSS 3.1 base score, v2 9.3
0.48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A Vulnerability of LG Electronic web OS TV Emulator could allow an attacker to escalate privileges and overwrite certain files. This vulnerability is due to wrong environment setting. An attacker could exploit this vulnerability through crafted configuration files and executable files.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://blog.recurity-labs.com/2021-02-03/webOS_Pt1.html ExploitThird Party Advisory
https://lists.debian.org/debian-lts-announce/2021/09/msg00018.html Mailing ListNot ApplicableThird Party Advisory
https://blog.recurity-labs.com/2021-02-03/webOS_Pt1.html ExploitThird Party Advisory
https://lists.debian.org/debian-lts-announce/2021/09/msg00018.html Mailing ListNot ApplicableThird Party Advisory

Track CVE-2020-9759 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-6317Lg webos insecure direct object reference vulnerabilityA prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without …EPSS 1.1%9.8CVE-2022-23730Lg webos improper access control vulnerabilityThe public API error causes for the attacker to be able to bypass API access control.EPSS 1.0%7.8CVE-2022-23731Lg webos permissions and access controls vulnerabilityV8 javascript engine (heap vulnerability) can cause privilege escalation ,which can impact on some webOS TV models.EPSS 0.63%7.8CVE-2022-23727Lg webos vulnerabilityThere is a privilege escalation vulnerability in some webOS TVs. Due to wrong setting environments, local attacker is able to perform specific operat…EPSS 0.23%7.2CVE-2023-6319Lg webos os command injection vulnerabilityA command injection vulnerability exists in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service on webOS version 4 …EPSS 6.4%7.2CVE-2023-6320Lg webos os command injection vulnerabilityA command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on webOS versions 5 and 6. A ser…EPSS 3.9%7.2CVE-2023-6318Lg webos os command injection vulnerabilityA command injection vulnerability exists in the processAnalyticsReport method from the com.webos.service.cloudupload service on webOS version 5 throu…EPSS 4.7%7.8CVE-2026-3502TrueConf Client update download lacks integrity check, enabling code executionTrueConf Client downloads application update code and applies it without verifying its integrity (CWE-494). An attacker who can influence the update …KEVEPSS 0.33%analysed

Source: NIST National Vulnerability Database (record CVE-2020-9759), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.