Back to news

vBulletin RCE Exploit Goes Public; LG Cracks Down on Smart TV Proxy Apps

Two security disclosures this week put unpatched forum software and smart TV app stores in the crosshairs of enterprise risk teams.

vBulletin RCE Exploit Goes Public; LG Cracks Down on Smart TV Proxy Apps

What happened

A working, publicly available exploit targeting vBulletin forum software was released on July 27, demonstrating how an attacker with no account or credentials can route a malicious request directly into PHP's eval() function and execute arbitrary code on a vulnerable server. SSD Secure Disclosure confirmed vBulletin versions 6.2.1 and below, as well as the 6.1.6 branch and earlier, are affected; the lower version boundary has not yet been established. Separately, LG Electronics USA announced plans to suspend smart TV apps on its webOS platform that covertly enroll users' televisions as residential proxy nodes, funneling third-party internet traffic through home networks without owner consent. The move follows researcher findings that more than 42 percent of apps available in the LG webOS store carried this behavior.

Why it matters for your business

The public release of a pre-authentication exploit dramatically lowers the skill threshold required to compromise any internet-facing vBulletin installation, meaning automated scanning and mass exploitation are now realistic threats rather than theoretical ones. Organizations running community forums or customer-facing discussion boards on vBulletin should treat patching as an emergency action, not a scheduled maintenance task. The LG proxy story carries a different but equally serious implication: smart TVs deployed in corporate lobbies, conference rooms, or employee lounges may be silently participating in proxy networks, potentially exposing organizational IP addresses and consuming bandwidth. Procurement and IT security teams should audit the app inventories of any internet-connected display hardware on corporate premises and apply firmware and app-store updates immediately.

What to watch next

Security researchers are likely to probe older vBulletin versions to establish the full scope of affected installations, and further technical detail in public exploit code could accelerate in-the-wild attacks over the coming days. On the smart TV front, LG's enforcement timeline and the precise technical mechanism it will use to detect and block proxy-enabling apps remain undefined, leaving a window during which affected apps may still be active. Broader regulatory scrutiny of smart device app stores — particularly around undisclosed data routing — is a trend worth monitoring as more vendors respond to similar research findings.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp