Buffer Overflow Vulnerability in Samsung SmartThings Hub HTTP Server
CVE-2018-3875
What is CVE-2018-3875?
A buffer overflow vulnerability was identified in the credentials handler of the video-core HTTP server on the Samsung SmartThings Hub. This issue arises when the video-core process improperly handles user-provided JSON payloads, leading to stack overflow conditions. Specifically, the strncpy function can overflow a destination buffer of 2,000 bytes when it processes an excessively long 'sessionToken'. Attackers can exploit this flaw to inject malicious data, potentially compromising the security of affected devices.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SmartThings Hub STH-ETH-250 Firmware version 0.20.17
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved