Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

No Patch for Flaw Exposing Hundreds of LG Cameras to Remote Hacking

LG Innotek LNV5110R security cameras are affected by a vulnerability that can be exploited for unauthenticated remote code execution.

Camera feeds exposed to hackers

Hundreds of LG security cameras are vulnerable to remote hacking due to a recently discovered flaw and they will not receive a patch.

The cybersecurity agency CISA revealed on Thursday that LG Innotek LNV5110R cameras are affected by an authentication bypass vulnerability that can allow an attacker to gain administrative access to the device.

The flaw, tracked as CVE-2025-7742 and assigned a ‘high severity’ rating, can allow an attacker to upload an HTTP POST request to the device’s non-volatile storage, which can result in remote code execution with elevated privileges, according to CISA.

LG Innotek has been notified, but said the vulnerability cannot be patched as the product has reached end of life.

Souvik Kandar, the MicroSec researcher credited by CISA for reporting the vulnerability, told SecurityWeek there are roughly 1,300 cameras that are exposed to the internet and which can be remotely hacked.

The researcher said an attacker could exploit the vulnerability to gain access to live streams, disrupt the camera, and for other malicious activities. 

Advertisement. Scroll to continue reading.

“This is a full unauthenticated remote code execution vulnerability,” Kandar explained. “An attacker can upload a reverse shell without any login, gain administrative privileges, execute arbitrary Linux commands, and use the device as a launching pad to pivot into internal networks.”

CISA said the impacted product is used worldwide, including in the commercial facilities critical infrastructure sector. 

SecurityWeek has reached out to LG Innotek for comment and will update this article if the company responds. 

Kandar said he reported 50 vulnerabilities this year, including in smart weather systems, seismic sensors, marine systems, routers, and OT devices, including AutomationDirect, Instantel and Lantronix products designed for industrial environments. 

Learn More at SecurityWeek’s ICS Cybersecurity Conference
The leading global conference series for Operations, Control Systems and OT/IT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.
ICS Cybersecurity Conference
October 27-30, 2025 | Atlanta
www.icscybersecurityconference.com

Related: 40,000 Security Cameras Exposed to Remote Hacking

Related: Vulnerabilities Allow Remote Hacking of Inaba Plant Monitoring Cameras

Related: Unpatched Edimax Camera Flaw Exploited Since at Least May 2024

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

With "Shadow AI" usage becoming prevalent in organizations, learn how to balance the need for rapid experimentation with the rigorous controls required for enterprise-grade deployment.

Register

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

People on the Move

Neill Feather has been named Chief Executive Officer at Point Wild.

Oasis Security has appointed Michael DeCesare as President.

Sterling Wilson has joined IGEL as Global Field CTO, Business Continuity and Disaster Recovery.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.