This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/installation/setThumbnailRc endpoint. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user.
Use CWE-22, Lg vendor hub and Lg Led Assistant product page to widen CVE-2023-4614 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-4613, CVE-2024-2862 and CVE-2023-4616 for nearby disclosures in the same product family.