← Vulnerability feed

Vulnerability record · CVE-2022-23730 · published 11 March 2022

CVE-2022-23730: Lg webos improper access control vulnerability

Lg · Webos

The public API error causes for the attacker to be able to bypass API access control.

9.8 CVSS 3.1 Critical EPSS 1.0% · top 37.9% CWE-284 · Improper access control
9.8CVSS 3.1 base score, v2 7.5
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

The public API error causes for the attacker to be able to bypass API access control.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-23730 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-6317Lg webos insecure direct object reference vulnerabilityA prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without …EPSS 1.1%7.8CVE-2022-23731Lg webos permissions and access controls vulnerabilityV8 javascript engine (heap vulnerability) can cause privilege escalation ,which can impact on some webOS TV models.EPSS 0.63%7.8CVE-2022-23727Lg webos vulnerabilityThere is a privilege escalation vulnerability in some webOS TVs. Due to wrong setting environments, local attacker is able to perform specific operat…EPSS 0.23%7.8CVE-2020-9759Lg webos download of code without integrity check vulnerabilityA Vulnerability of LG Electronic web OS TV Emulator could allow an attacker to escalate privileges and overwrite certain files. This vulnerability is…EPSS 0.48%7.2CVE-2023-6319Lg webos os command injection vulnerabilityA command injection vulnerability exists in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service on webOS version 4 …EPSS 6.4%7.2CVE-2023-6320Lg webos os command injection vulnerabilityA command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on webOS versions 5 and 6. A ser…EPSS 3.9%7.2CVE-2023-6318Lg webos os command injection vulnerabilityA command injection vulnerability exists in the processAnalyticsReport method from the com.webos.service.cloudupload service on webOS version 5 throu…EPSS 4.7%7.8CVE-2026-81963Windows Update Stack link-following privilege escalationWindows Update Stack resolves links improperly before accessing files, a link-following flaw (CWE-59) compounded by improper access control (CWE-284)…KEVEPSS 0.39%analysed

Source: NIST National Vulnerability Database (record CVE-2022-23730), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.