A vulnerability has been discovered in AC Smart II where passwords can be changed without authorization. This page contains a hidden form for resetting the administrator password. The attacker can manipulate the page using developer tools to display and use the form. This form allows you to change the administrator password without verifying login status or user permissions.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://lgsecurity.lge.com/bulletins |
|
History
Mon, 15 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Sep 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lg
Lg ac Smart |
|
| Vendors & Products |
Lg
Lg ac Smart |
Sun, 14 Sep 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been discovered in AC Smart II where passwords can be changed without authorization. This page contains a hidden form for resetting the administrator password. The attacker can manipulate the page using developer tools to display and use the form. This form allows you to change the administrator password without verifying login status or user permissions. | |
| Title | Unauth Admin Reset Password on AC Smart II | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: LGE
Published: 2025-09-14T12:43:30.393Z
Updated: 2025-09-15T15:58:31.372Z
Reserved: 2025-09-10T01:26:32.811Z
Link: CVE-2025-10204
Updated: 2025-09-15T15:58:26.399Z
Status : Awaiting Analysis
Published: 2025-09-14T13:15:32.067
Modified: 2025-09-15T15:21:42.937
Link: CVE-2025-10204
No data.