Samsung Smartthings Hub Sth-Eth-250 vulnerabilities
23 known vulnerabilities affecting samsung/smartthings_hub_sth-eth-250.
Total CVEs
23
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL12HIGH11
Vulnerabilities
Page 2 of 2
CVE-2018-3906P3HIGHCVSS 8.2vFirmware version 0.20.172018-09-21
CVE-2018-3906 [HIGH] CWE-787 CVE-2018-3906: An exploitable stack-based buffer overflow vulnerability exists in the retrieval of a database field
An exploitable stack-based buffer overflow vulnerability exists in the retrieval of a database field in video-core's HTTP server of Samsung SmartThings Hub. The video-core process insecurely extracts the shard.videoHostURL field from its SQLite database, leading to a buffer overflow on the stack. An attacker can send an HTTP request to trigger this vuln
nvd
CVE-2018-3912P3HIGHCVSS 7.8vFirmware version 0.20.172018-08-23
CVE-2018-3912 [HIGH] CWE-787 CVE-2018-3912: On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process
On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process insecurely extracts the fields from the "shard" table of its SQLite database, leading to a buffer overflow on the stack. The strcpy call overflows the destination buffer, which has a size of 128 bytes. An attacker can send an arbitrarily long "secretKey"
nvd
CVE-2018-3915P3HIGHCVSS 8.2vFirmware version 0.20.172018-09-21
CVE-2018-3915 [HIGH] CWE-787 CVE-2018-3915: An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields
An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The strcpy call overflows the destination buffer, which has a size of 64 bytes. An attacker can send an arbitrarily long "bucket" value in order to exploit
nvd
← Previous2 / 2