Samsung SmartThings Hub video-core... CVE-2018-3907,CVE-2018-3908,CVE-2018-3909

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Summary Multiple exploitable vulnerabilities exist in the REST parser of `video-core`'s HTTP server of the Samsung SmartThings Hub. The `video-core` process incorrectly handles pipelined HTTP requests, which allows successive requests to overwrite the previously parsed HTTP method, URL and body. An attacker can send an HTTP request to trigger this vulnerability. ### Tested Versions Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17 ### Product URLs [https://www.smartthings.com/products/smartthings-hub](https://www.smartthings.com/products/smartthings-hub) ### CVSSv3 Score 9.1 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H ### CWE CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') ### Details Samsung produces a series of devices aimed at controlling and monitoring a home, such as wall switches, LED bulbs, thermostats and cameras. One of those is the Samsung SmartThings Hub, a central controller which allows an end user to use their...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息