The /api/changePw endpoint in LG LED Assistant allows unauthenticated password resets when requests are considered to come from localhost. An attacker can spoof the X-Forwarded-For header with value 127.0.0.1 to trigger the behavior and receive a success response.
id: CVE-2024-2862
info:
name: LG LED Assistant - Unauthenticated Password Reset
author: beginee
...