Samsung Sth-Eth-250 Firmware vulnerabilities
40 known vulnerabilities affecting samsung/sth-eth-250_firmware.
Total CVEs
40
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL19HIGH18MEDIUM3
Vulnerabilities
Page 1 of 2
CVE-2018-3856P2CRITICALCVSS 9.9v0.20.172018-08-23
CVE-2018-3856 [CRITICAL] CWE-88 CVE-2018-3856: An exploitable vulnerability exists in the smart cameras RTSP configuration of the Samsung SmartThin
An exploitable vulnerability exists in the smart cameras RTSP configuration of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The device incorrectly handles spaces in the URL field, leading to an arbitrary operating system command injection. An attacker can send a series of HTTP requests to trigger this vulnerability.
nvd
CVE-2018-3902P3CRITICALCVSS 9.9v0.20.172018-08-23
CVE-2018-3902 [CRITICAL] CWE-787 CVE-2018-3902: An exploitable buffer overflow vulnerability exists in the camera "replace" feature of video-core's
An exploitable buffer overflow vulnerability exists in the camera "replace" feature of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The video-core process incorrectly extracts the URL field from a user-controlled JSON payload, leading to a buffer overflow on the stack. An attacker can send an
nvd
CVE-2018-3903P3CRITICALCVSS 9.9v0.20.172018-08-23
CVE-2018-3903 [CRITICAL] CWE-787 CVE-2018-3903: On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process
On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. An attacker can send an HTTP request to trigger this vulnerability. The memcpy call overflows the destination buffer, which has a size of 512
nvd
CVE-2018-3904P3CRITICALCVSS 9.9v0.20.172018-08-27
CVE-2018-3904 [CRITICAL] CWE-787 CVE-2018-3904: An exploitable buffer overflow vulnerability exists in the camera 'update' feature of video-core's H
An exploitable buffer overflow vulnerability exists in the camera 'update' feature of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. An attacker can send an HTTP request to tr
nvd
CVE-2018-3872P3CRITICALCVSS 9.9v0.20.172018-08-23
CVE-2018-3872 [CRITICAL] CWE-119 CVE-2018-3872: An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP
An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly extracts the videoHostUrl field from a user-controlled JSON payload, leading to a buffer overflow on the stack. An attacker can send an HTTP re
nvd
CVE-2018-3863P3CRITICALCVSS 9.9v0.20.172018-08-23
CVE-2018-3863 [CRITICAL] CWE-787 CVE-2018-3863: On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process
On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. An attacker can send an HTTP request to trigger this vulnerability. A strcpy overflows the destination buffer, which has a size of 40 bytes. A
nvd
CVE-2018-3905P3CRITICALCVSS 9.9v0.20.172018-08-23
CVE-2018-3905 [CRITICAL] CWE-119 CVE-2018-3905: An exploitable buffer overflow vulnerability exists in the camera "create" feature of video-core's H
An exploitable buffer overflow vulnerability exists in the camera "create" feature of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The video-core process incorrectly extracts the "state" field from a user-controlled JSON payload, leading to a buffer overflow on the stack. An attacker can send
nvd
CVE-2018-3867P3CRITICALCVSS 9.9v0.20.172018-08-23
CVE-2018-3867 [CRITICAL] CWE-787 CVE-2018-3867: An exploitable stack-based buffer overflow vulnerability exists in the samsungWifiScan callback noti
An exploitable stack-based buffer overflow vulnerability exists in the samsungWifiScan callback notification of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The video-core process incorrectly handles the answer received from a smart camera, leading to a buffer overflow on the stack. An attack
nvd
CVE-2018-3907P3CRITICALCVSS 10.0v0.20.172018-08-24
CVE-2018-3907 [CRITICAL] CWE-444 CVE-2018-3907: An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung Sm
An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly handles pipelined HTTP requests, which allows successive requests to overwrite the previously parsed HTTP method, 'on_url' callback. An attacker can send an HTTP
nvd
CVE-2018-3878P3CRITICALCVSS 9.9v0.20.172018-08-23
CVE-2018-3878 [CRITICAL] CWE-119 CVE-2018-3878: Multiple exploitable buffer overflow vulnerabilities exist in the credentials handler of video-core'
Multiple exploitable buffer overflow vulnerabilities exist in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. A strncpy overflows the dest
nvd
CVE-2018-3877P3CRITICALCVSS 9.9v0.20.172018-09-21
CVE-2018-3877 [CRITICAL] CWE-119 CVE-2018-3877: An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP
An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy overflows the destination buffer, which has a size of 160 bytes. An attacker can send an arbitrarily long "directory" value in order to exploit this vulnerability.
nvd
CVE-2018-3873P3CRITICALCVSS 9.9v0.20.172018-09-21
CVE-2018-3873 [CRITICAL] CWE-119 CVE-2018-3873: An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP
An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy overflows the destination buffer, which has a size of 128 bytes. An attacker can send an arbitrarily long "secretKey" value in order to exploit this vulnerability.
nvd
CVE-2018-3874P3CRITICALCVSS 9.9v0.20.172018-09-21
CVE-2018-3874 [CRITICAL] CWE-119 CVE-2018-3874: An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP
An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy overflows the destination buffer, which has a size of 32 bytes. An attacker can send an arbitrarily long "accessKey" value in order to exploit this vulnerability.
nvd
CVE-2018-3875P3CRITICALCVSS 9.9v0.20.172018-09-10
CVE-2018-3875 [CRITICAL] CWE-119 CVE-2018-3875: An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP
An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. The strncpy overflows the destination buffer, whi
nvd
CVE-2018-3866P3CRITICALCVSS 9.9v0.20.172018-08-23
CVE-2018-3866 [CRITICAL] CWE-787 CVE-2018-3866: An exploitable buffer overflow vulnerability exists in the samsungWifiScan handler of video-core's H
An exploitable buffer overflow vulnerability exists in the samsungWifiScan handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. The strcpy at [8] overflows the destinatio
nvd
CVE-2018-3880P3CRITICALCVSS 9.9v0.20.172018-08-23
CVE-2018-3880 [CRITICAL] CWE-787 CVE-2018-3880: An exploitable stack-based buffer overflow vulnerability exists in the database 'find-by-cameraId' f
An exploitable stack-based buffer overflow vulnerability exists in the database 'find-by-cameraId' functionality of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly handles existing records inside its SQLite database, leading to a buffer overflow on the stack. An attacker
nvd
CVE-2018-3917P3CRITICALCVSS 9.9v0.20.172018-08-23
CVE-2018-3917 [CRITICAL] CWE-119 CVE-2018-3917: On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process
On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process insecurely extracts the fields from the "shard" table of its SQLite database, leading to a buffer overflow on the stack. An attacker can send an HTTP request to trigger this vulnerability. The strcpy call overflows the destination buffer, which has a
nvd
CVE-2018-3879P3HIGHCVSS 8.8v0.20.172018-08-23
CVE-2018-3879 [HIGH] CWE-89 CVE-2018-3879: An exploitable JSON injection vulnerability exists in the credentials handler of video-core's HTTP s
An exploitable JSON injection vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The video-core process incorrectly parses the user-controlled JSON payload, leading to a JSON injection which in turn leads to a SQL injection in the video-core database. A
nvd
CVE-2018-3895P3HIGHCVSS 8.8v0.20.172018-08-28
CVE-2018-3895 [HIGH] CWE-120 CVE-2018-3895: An exploitable buffer overflow vulnerability exists in the /cameras/XXXX/clips handler of video-core
An exploitable buffer overflow vulnerability exists in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 Firmware version 0.20.17. The strncpy call overflows the destination buffer, which has a size of 52 bytes. An attacker can send an arbitrarily long 'endTime' value in order to exploit this vulnerabilit
nvd
CVE-2018-3925P3CRITICALCVSS 9.9v0.20.172018-08-23
CVE-2018-3925 [CRITICAL] CWE-119 CVE-2018-3925: An exploitable buffer overflow vulnerability exists in the remote video-host communication of video-
An exploitable buffer overflow vulnerability exists in the remote video-host communication of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The video-core process insecurely parses the AWSELB cookie while communicating with remote video-host servers, leading to a buffer overflow on the heap. A
nvd
1 / 2Next →