Buffer Overflow Vulnerability in Samsung SmartThings Hub
CVE-2018-3902
9.9CRITICAL
Summary
A buffer overflow vulnerability exists in the 'replace' feature of the HTTP server in Samsung's SmartThings Hub STH-ETH-250 devices running firmware version 0.20.17. This issue arises from improper extraction of a user-controlled JSON payload's URL field, which may result in a buffer overflow on the stack. An attacker capable of sending a crafted HTTP request could exploit this vulnerability to execute arbitrary code on the affected device, potentially compromising the security of the smart home environment.
Affected Version(s)
SmartThings Hub STH-ETH-250 Firmware version 0.20.17
References
CVSS V3.1
Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved