← Vulnerability feed

Vulnerability record · CVE-2023-6319 · published 9 April 2024

CVE-2023-6319: Lg webos os command injection vulnerability

Lg · Webos

A command injection vulnerability exists in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service on webOS version 4 through 7. A series of specially crafted requests can lead to command execution as the root user. An attacker can make authenticated requests to trigger this vulnerability. * webOS 4.9.7 - 5.30.40 running on LG43UM7000PLA  * webOS 5.5.0 - 04.50.51 running on OLED55CXPUA  * webOS 6.3.3-442 (kisscurl-kinglake) - 03.36.50 running on OLED48C1PUB  * webOS 7.3.1-43 (mullet-mebin) - 03.33.85 running on OLED55A23LA

7.2 CVSS 3.1 High EPSS 6.4% · top 6.5% CWE-78 · OS command injection
7.2CVSS 3.1 base score
6.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A command injection vulnerability exists in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service on webOS version 4 through 7. A series of specially crafted requests can lead to command execution as the root user. An attacker can make authenticated requests to trigger this vulnerability. * webOS 4.9.7 - 5.30.40 running on LG43UM7000PLA  * webOS 5.5.0 - 04.50.51 running on OLED55CXPUA  * webOS 6.3.3-442 (kisscurl-kinglake) - 03.36.50 running on OLED48C1PUB  * webOS 7.3.1-43 (mullet-mebin) - 03.33.85 running on OLED55A23LA

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-6319 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-6317Lg webos insecure direct object reference vulnerabilityA prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without …EPSS 1.1%9.8CVE-2022-23730Lg webos improper access control vulnerabilityThe public API error causes for the attacker to be able to bypass API access control.EPSS 1.0%7.8CVE-2022-23731Lg webos permissions and access controls vulnerabilityV8 javascript engine (heap vulnerability) can cause privilege escalation ,which can impact on some webOS TV models.EPSS 0.63%7.8CVE-2022-23727Lg webos vulnerabilityThere is a privilege escalation vulnerability in some webOS TVs. Due to wrong setting environments, local attacker is able to perform specific operat…EPSS 0.23%7.8CVE-2020-9759Lg webos download of code without integrity check vulnerabilityA Vulnerability of LG Electronic web OS TV Emulator could allow an attacker to escalate privileges and overwrite certain files. This vulnerability is…EPSS 0.48%7.2CVE-2023-6320Lg webos os command injection vulnerabilityA command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on webOS versions 5 and 6. A ser…EPSS 3.9%7.2CVE-2023-6318Lg webos os command injection vulnerabilityA command injection vulnerability exists in the processAnalyticsReport method from the com.webos.service.cloudupload service on webOS version 5 throu…EPSS 4.7%8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed

Source: NIST National Vulnerability Database (record CVE-2023-6319), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.