Description
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics SmartShare allows SQL Injection.

This issue affects SmartShare: through 2.3.1712.1202, which is supported on Microsoft Windows 10 and earlier versions.
Published: 2026-07-30
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper sanitization of special elements in SQL commands creates a classic SQL injection flaw, classified as CWE‑89. The flaw permits an attacker who supplies crafted input to the SmartShare application to execute arbitrary SQL statements on the underlying database. As a result, the attacker could read confidential information, alter or delete data, or potentially gain elevated privileges if the database connection has higher rights.

Affected Systems

LG Electronics SmartShare products up through version 2.3.1712.1202 are affected. These versions run on Microsoft Windows 10 and earlier operating systems.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity level, however the EPSS score of less than 1% suggests current exploitation risk is low. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is likely via untrusted user input presented in the SmartShare interface—such as URL parameters or form fields—though the exact mechanics are not detailed. No official fix or workaround is documented in the provided references, meaning defenses must rely on patching when available or mitigating the attack surface.

Generated by OpenCVE AI on August 3, 2026 at 11:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the latest SmartShare update from LG’s security bulletin to address the injection flaw.
  • If an update is not yet available, restrict SmartShare exposure by limiting network access to trusted sources and disabling any features that expose database interfaces.
  • Enable detailed database logging and monitor for abnormal query patterns to detect potential exploitation attempts.

Generated by OpenCVE AI on August 3, 2026 at 11:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title SQL Injection Vulnerability in LG SmartShare

Thu, 30 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics SmartShare allows SQL Injection. This issue affects SmartShare: through 2.3.1712.1202, which is supported on Microsoft Windows 10 and earlier versions.
First Time appeared Lg Electronics
Lg Electronics smartshare
Weaknesses CWE-89
CPEs cpe:2.3:a:lg_electronics:smartshare:*:*:windows:*:*:*:*:*
Vendors & Products Lg Electronics
Lg Electronics smartshare
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Lg Electronics Smartshare
cve-icon MITRE

Status: PUBLISHED

Assigner: LGE

Published:

Updated: 2026-07-30T13:13:34.051Z

Reserved: 2026-07-16T07:14:00.895Z

Link: CVE-2026-15929

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-07-30T02:16:45.360

Modified: 2026-07-30T19:15:36.947

Link: CVE-2026-15929

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T11:30:03Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')