Vulnerability record · CVE-2024-2863 · published 25 March 2024
CVE-2024-2863: LG LED Assistant path traversal via file upload
Lg · Lg Led Assistant
LG LED Assistant is affected by a path traversal flaw reached through file upload, allowing remote attackers to write or reach files outside the intended directory. The record gives no affected version range, so defenders must rely on the vendor advisory to identify fixed builds. With a CVSS 3.1 score of 9.8 and no authentication or user interaction required, this is a high-priority exposure for any internet-facing instance.
Description
This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, combined with a very high EPSS percentile, makes this an urgent patch-or-isolate case.
What it is
LG LED Assistant is affected by a path traversal flaw reached through file upload, allowing remote attackers to write or reach files outside the intended directory. The record gives no affected version range, so defenders must rely on the vendor advisory to identify fixed builds. With a CVSS 3.1 score of 9.8 and no authentication or user interaction required, this is a high-priority exposure for any internet-facing instance.
Impact
An unauthenticated remote attacker can traverse paths through the upload function, which can lead to writing or accessing files outside the intended location and potentially full compromise of confidentiality, integrity and availability.
Attack surface
The vector is network-reachable (AV:N) with low complexity, no privileges and no user interaction, so the upload endpoint is directly exploitable by anyone who can reach the service. No authentication is required per the CVSS vector.
Exploitation
CVE-2024-2863 is not listed in CISA KEV and no ransomware use is documented, but EPSS is 0.63999 (99.185th percentile), indicating a high modeled likelihood of exploitation. The only references are vendor advisories, so no public exploit code is confirmed by this record.
What to do
- Apply the fixed version from the LG security bulletin for LED Assistant; treat the vendor advisory as the authoritative patch source.
- Restrict network access to the LED Assistant upload interface, keeping it off the public internet and behind allowlists or a VPN.
- Validate and normalize uploaded filenames and paths server-side, rejecting traversal sequences and absolute paths.
- Run the service with least privilege and confine its file writes to a dedicated directory.
- Monitor the vendor advisory page for updated affected-version details, which this record does not provide.
Detection
- Review upload endpoint logs for filenames or paths containing ../, ..\, encoded traversal sequences, or absolute paths.
- Alert on file creation or modification outside the expected upload directory by the LED Assistant process.
- Baseline normal upload volume and flag anomalous or burst uploads from single source IPs.
- Watch for unexpected outbound connections or new files in web-accessible directories following upload activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://lgsecurity.lge.com/bulletins/idproducts#updateDetails | Vendor Advisory |
| https://lgsecurity.lge.com/bulletins/idproducts#updateDetails | Vendor Advisory |
Track CVE-2024-2863 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-2863), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.