Buffer Overflow Vulnerability in Samsung SmartThings Hub
CVE-2018-3902
What is CVE-2018-3902?
A buffer overflow vulnerability exists in the 'replace' feature of the HTTP server in Samsung's SmartThings Hub STH-ETH-250 devices running firmware version 0.20.17. This issue arises from improper extraction of a user-controlled JSON payload's URL field, which may result in a buffer overflow on the stack. An attacker capable of sending a crafted HTTP request could exploit this vulnerability to execute arbitrary code on the affected device, potentially compromising the security of the smart home environment.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SmartThings Hub STH-ETH-250 Firmware version 0.20.17
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved