ZeroHour

CVE-2018-14839

KEV PoC niche

Unauthenticated Command Injection RCE in LG N1A1 NAS

CISA: LG N1A1 NAS Remote Command Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
89%p100
Published
()
KEV added
AI analysis

LG N1A1 NAS firmware 3718.510 contains an OS command injection flaw (CWE-78) that allows an unauthenticated attacker to execute arbitrary commands on the device. The flaw is triggered over the network by sending crafted parameters in an HTTP POST request to the NAS web interface, requiring no credentials or user interaction. Successful exploitation gives the attacker remote code execution on the device, with full confidentiality, integrity, and availability impact per the critical 9.8 CVSS score. Only LG N1A1 NAS devices (specifically firmware 3718.510 per the disclosure) are affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25, carries a very high 89.4% EPSS probability of exploitation within 30 days, and a public proof-of-concept write-up is available.

What to do: Apply updates per LG/vendor instructions as required by CISA's KEV listing; given the device's age, if no updated firmware is obtainable, replace or isolate the NAS. Immediately check whether the N1A1 web interface is exposed to the internet (port forwarding, UPnP) and restrict HTTP access to trusted networks or a VPN. Review device logs for suspicious HTTP POST requests and unexpected commands as evidence of compromise.

Affected
LG N1A1 NAS (firmware)3718.510 (confirmed affected; other firmware versions not specified in available data)
Estimated exposure
nichelikely low thousands of devices at most worldwide, with only a small fraction internet-exposed (estimate; no public scan counts available) — The affected product is a single, long-discontinued consumer/SOHO NAS model, so the installed base is inherently limited and typical home deployments are not directly internet-exposed; no public internet-exposure scan counts were available…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

LG N1A1 NAS 3718.510 is affected by: Remote Command Execution. The impact is: execute arbitrary code (remote). The attack vector is: HTTP POST with parameters.

CISA Known Exploited Vulnerability
Affected
LG N1A1 NAS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
lg
Products
n1a1 firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news