← Vulnerability feed

Vulnerability record · CVE-2022-23727 · published 28 January 2022

CVE-2022-23727: Lg webos vulnerability

Lg · Webos

There is a privilege escalation vulnerability in some webOS TVs. Due to wrong setting environments, local attacker is able to perform specific operation to exploit this vulnerability. Exploitation may cause the attacker to obtain a higher privilege

7.8 CVSS 3.1 High EPSS 0.23% · top 88.0%
7.8CVSS 3.1 base score, v2 4.6
0.23%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

There is a privilege escalation vulnerability in some webOS TVs. Due to wrong setting environments, local attacker is able to perform specific operation to exploit this vulnerability. Exploitation may cause the attacker to obtain a higher privilege

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-23727 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-6317Lg webos insecure direct object reference vulnerabilityA prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without …EPSS 1.1%9.8CVE-2022-23730Lg webos improper access control vulnerabilityThe public API error causes for the attacker to be able to bypass API access control.EPSS 1.0%7.8CVE-2022-23731Lg webos permissions and access controls vulnerabilityV8 javascript engine (heap vulnerability) can cause privilege escalation ,which can impact on some webOS TV models.EPSS 0.63%7.8CVE-2020-9759Lg webos download of code without integrity check vulnerabilityA Vulnerability of LG Electronic web OS TV Emulator could allow an attacker to escalate privileges and overwrite certain files. This vulnerability is…EPSS 0.48%7.2CVE-2023-6319Lg webos os command injection vulnerabilityA command injection vulnerability exists in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service on webOS version 4 …EPSS 6.4%7.2CVE-2023-6320Lg webos os command injection vulnerabilityA command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on webOS versions 5 and 6. A ser…EPSS 3.9%7.2CVE-2023-6318Lg webos os command injection vulnerabilityA command injection vulnerability exists in the processAnalyticsReport method from the com.webos.service.cloudupload service on webOS version 5 throu…EPSS 4.7%

Source: NIST National Vulnerability Database (record CVE-2022-23727), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.