An authentication vulnerability exists in the LG Innotek camera model LNV5110R firmware that allows a malicious actor to upload an HTTP POST request to the devices non-volatile storage. This action may result in remote code execution that allows an attacker to run arbitrary commands on the target device at the administrator privilege level.
History

Fri, 25 Jul 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Jul 2025 23:45:00 +0000

Type Values Removed Values Added
Description An authentication vulnerability exists in the LG Innotek camera model LNV5110R firmware that allows a malicious actor to upload an HTTP POST request to the devices non-volatile storage. This action may result in remote code execution that allows an attacker to run arbitrary commands on the target device at the administrator privilege level.
Title Authentication Bypass in LG Innotek Camera
Weaknesses CWE-288
References
Metrics cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: LGE

Published: 2025-07-24T23:28:32.443Z

Updated: 2025-07-25T17:33:14.255Z

Reserved: 2025-07-17T07:42:25.697Z

Link: CVE-2025-7742

cve-icon Vulnrichment

Updated: 2025-07-25T17:33:09.534Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-25T00:15:24.960

Modified: 2025-07-25T15:29:19.837

Link: CVE-2025-7742

cve-icon Redhat

No data.