← Vulnerability feed

Vulnerability record · CVE-2024-2863 · published 25 March 2024

CVE-2024-2863: LG LED Assistant path traversal via file upload

Lg · Lg Led Assistant

LG LED Assistant is affected by a path traversal flaw reached through file upload, allowing remote attackers to write or reach files outside the intended directory. The record gives no affected version range, so defenders must rely on the vendor advisory to identify fixed builds. With a CVSS 3.1 score of 9.8 and no authentication or user interaction required, this is a high-priority exposure for any internet-facing instance.

9.8 CVSS 3.1 Critical EPSS 64% · top 0.8% CWE-35 · CWE-35CWE-22 · Path traversal
9.8CVSS 3.1 base score
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, combined with a very high EPSS percentile, makes this an urgent patch-or-isolate case.

What it is

LG LED Assistant is affected by a path traversal flaw reached through file upload, allowing remote attackers to write or reach files outside the intended directory. The record gives no affected version range, so defenders must rely on the vendor advisory to identify fixed builds. With a CVSS 3.1 score of 9.8 and no authentication or user interaction required, this is a high-priority exposure for any internet-facing instance.

Impact

An unauthenticated remote attacker can traverse paths through the upload function, which can lead to writing or accessing files outside the intended location and potentially full compromise of confidentiality, integrity and availability.

Attack surface

The vector is network-reachable (AV:N) with low complexity, no privileges and no user interaction, so the upload endpoint is directly exploitable by anyone who can reach the service. No authentication is required per the CVSS vector.

Exploitation

CVE-2024-2863 is not listed in CISA KEV and no ransomware use is documented, but EPSS is 0.63999 (99.185th percentile), indicating a high modeled likelihood of exploitation. The only references are vendor advisories, so no public exploit code is confirmed by this record.

What to do

  • Apply the fixed version from the LG security bulletin for LED Assistant; treat the vendor advisory as the authoritative patch source.
  • Restrict network access to the LED Assistant upload interface, keeping it off the public internet and behind allowlists or a VPN.
  • Validate and normalize uploaded filenames and paths server-side, rejecting traversal sequences and absolute paths.
  • Run the service with least privilege and confine its file writes to a dedicated directory.
  • Monitor the vendor advisory page for updated affected-version details, which this record does not provide.

Detection

  • Review upload endpoint logs for filenames or paths containing ../, ..\, encoded traversal sequences, or absolute paths.
  • Alert on file creation or modification outside the expected upload directory by the LED Assistant process.
  • Baseline normal upload volume and flag anomalous or burst uploads from single source IPs.
  • Watch for unexpected outbound connections or new files in web-accessible directories following upload activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-2863 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-2862LG LED Assistant improper authentication allows anonymous password resetLG LED Assistant contains an improper authentication flaw (CWE-287) tied to weak password recovery (CWE-640). A remote, unauthenticated attacker can …EPSS 51%analysed9.8CVE-2023-4614Lg led assistant path traversal vulnerabilityThis vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to…EPSS 2.5%9.8CVE-2023-4613Lg led assistant path traversal vulnerabilityThis vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to…EPSS 2.5%7.5CVE-2023-4615Lg led assistant path traversal vulnerabilityThis vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not req…EPSS 1.6%7.5CVE-2023-4616Lg led assistant path traversal vulnerabilityThis vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not req…EPSS 1.6%9.4CVE-2025-62593Ray browser-based RCE via insufficient User-Agent guardRay, an AI compute engine, contains a critical remote code execution flaw before version 2.52.0. Its defense against browser-based attacks relies on …KEVEPSS 62%analysed8.1CVE-2008-4128Cisco IOS HTTP Administration CSRF allows arbitrary command executionThe HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router is vulnerable to multiple cross-site request forgery flaws.…KEVEPSS 34%analysed8.4CVE-2025-8088WinRAR path traversal lets crafted archives execute codeCVE-2025-8088 is a path traversal flaw in the Windows version of WinRAR that allows attackers to execute arbitrary code by crafting malicious archive…KEVEPSS 94%analysed

Source: NIST National Vulnerability Database (record CVE-2024-2863), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.