Buffer Overflow Vulnerability in Samsung SmartThings Hub Video-Core
CVE-2018-3897
What is CVE-2018-3897?
A buffer overflow vulnerability exists in the HTTP server of the Samsung SmartThings Hub's video-core component. This issue arises from improper handling of user-controlled JSON payloads, specifically within the /cameras/XXXX/clips handler. The process wrongly extracts data from incoming requests, enabling an attacker to manipulate the 'callbackUrl' field. This can lead to an overflow in the stack memory due to the strncpy function exceeding its intended buffer size of 52 bytes, potentially allowing remote code execution and system compromise.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SmartThings Hub STH-ETH-250 Firmware version 0.20.17
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved