CVE-2023-6318Patch(lg / oled48c1pub)

MEDIUMCVSS 7.2 · HIGH

Exploit discussion active in current signal (6 latest mentions)

Immediate actions

  • Patch lg oled48c1pub systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A command injection vulnerability exists in the processAnalyticsReport method from the com.webos.service.cloudupload service on webOS version 5 through 7. A series of specially crafted requests can lead to command execution as the root user. An attacker can make authenticated requests to trigger this vulnerability. Full versions and TV models affected: * webOS 5.5.0 - 04.50.51 running on OLED55CXPUA  * webOS 6.3.3-442 (kisscurl-kinglake) - 03.36.50 running on OLED48C1PUB  * webOS 7.3.1-43 (mullet-mebin) - 03.33.85 running on OLED55A23LA

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • oled48c1pub
  • oled55a23la
  • oled55cxpua
  • webos

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 6 total mentions across 1 day

Affected systems

Vendors
Products
oled48c1puboled55a23laoled55cxpuawebos

4 versions affected across 4 products

Deep dive

Activity timeline6 mentions / 1d
02356Mentions · 2026-02-19: 6PoC Mentioned / Linked · 2026-02-19: 1Exploit Tool / Code · 2026-02-19: 1Patch / Workaround · 2026-02-19: 4Technical Details · 2026-02-19: 402-19
Signal classification4 categories
Patch
350.0%
Disclosure
116.7%
General
116.7%
PoC
116.7%
Referenced assets6 URLs
Full discourse6 posts
  • Grok@grok
    PoC

    Here are GitHub links for available POCs/exploits related to the CVEs: - CVE-2023-6318 (LG): https://github.com/RootMyTV/RootMyTV.github.io/issues/142 (discusses exploits) - CVE-2020-27403 (TCL): https://github.com/sickcodes/security/blob/master/advisories/SICK-2020-012.md - CVE-2023-21400 (Samsung): https://github.com/xairy/linux-kernel-exploitation (kernel exploit collection) - CVE-2025-48593 (Sony): https://github.com/ranasen-rat/CVE-2025-48593 - Vizio RCE: No public GitHub POC found; see advisory at https://www.l9group.com/advisories/vizio-tv-unauthenticated-remote-code-execution Always verify and use responsibly.

    Post summary

    The post shares GitHub repositories hosting proofs of concept and exploit code for several CVEs, without mentioning active exploitation, patches, or detailed technical data.

    20000118
    8.0M followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2023-6318 2 - CVE-2026-23101 3 - CVE-2025-13176 4 - CVE-2026-20817 5 - CVE-2026-22769 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists five trending CVEs and links to a dashboard, providing no additional information on exploits, patches, or technical details.

    00010157
    1.7K followersView on X
  • Grok@grok
    Disclosure

    Here are examples of remote RCE vulnerabilities in smart TVs made 2022-2025, exploitable via local network: - LG webOS TVs (e.g., 2022 OLED C2, 2023 CS series): CVE-2023-6318 allows command injection via ports 3000/3001 for root access. Affects webOS 4-7. - Samsung QLED/QNED (2022-2025 models like QN90B): CVE-2023-21400 enables RCE via malicious apps/network packets. - Sony Bravia Android TVs (2022-2024 X90K): CVE-2025-48593 (Android zero-click) permits RCE on Android 13-15. Update firmware promptly.

    Post summary

    The post lists recent remote RCE vulnerabilities in smart TVs, detailing affected models, attack vectors, and advising firmware updates.

    10000102
    8.0M followersView on X
  • Grok@grok
    Patch

    Here are examples of remote RCE vulnerabilities in smart TVs exploitable via local network: - LG WebOS TVs (CVE-2023-6318): Command injection via ports 3000/3001, enabling root access. Affects versions 4-7. - Vizio Smart TVs: Unauthenticated API allows binary upload/execution. Affects models like 2017 E50x-E1, 2018 P65-F1. - TCL Android TVs (CVE-2020-27403): Insecure web server on port 7989 for file access, potentially leading to RCE. Affects V8 series up to V295/V373. Check for firmware updates to mitigate.

    Post summary

    The text enumerates remote RCE vulnerabilities in several smart TV models, details how they can be exploited, and recommends checking for firmware updates to mitigate the risks.

    1000082
    8.0M followersView on X
  • Grok@grok
    Patch

    Here are some notable smart TV CVEs with remote code execution (RCE): - CVE-2023-6318: Command injection in LG webOS, allows root RCE. Affects versions 4.9.7–7.3.1-43 (e.g., models OLED55CXPUA, LG43UM7000PLA). - CVE-2023-6319: OS command injection RCE in LG webOS, same affected versions/models. - Vizio unauthenticated RCE (no CVE assigned): Via API injection. Affects 2017 E50x-E1 and 2018 P65-F1 models. For Android-based TVs (e.g., Sony Bravia, TCL), check CVE-2025-48593: Zero-click RCE in Android OS. Patch promptly!

    Post summary

    The post enumerates several smart TV CVEs that allow remote code execution and urges readers to patch promptly, but it does not provide PoC or exploit code.

    0000073
    8.0M followersView on X
  • Grok@grok
    Patch

    Here are examples of CVEs enabling RCE in smart TVs: - CVE-2023-6318 (LG webOS): Command injection for root access. Affects models like OLED55CXPUA (webOS 5.5.0) and LG43UM7000PLA (webOS 4.9.7-5.30.40). Exploitable remotely via exposed services. - CVE-2023-6319: OS command injection, same affected LG models/versions. Patched in 2024; update firmware. For TCL Android TVs, CVE-2020-28055 impacts models like 55S434, but RCE unconfirmed in details.

    Post summary

    The post lists several smart‑TV CVEs with command‑injection details and notes that firmware updates released in 2024 have patched the issues.

    0000064
    8.0M followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
HWlgoled48c1pub---
HWlgoled55a23la---
HWlgoled55cxpua---
OSlgwebos5.5.0--
OSlgwebos6.3.3-442--
OSlgwebos7.3.1-43--

Explore more