An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly handles pipelined HTTP requests, which allows successive requests to overwrite the previously parsed HTTP method, 'on_url' callback. An attacker can send an HTTP request to trigger this vulnerability.
2018-08-24T00:29:00.210
2024-11-21T04:06:16.613
Modified
CVSSv3.1: 10.0 (CRITICAL)
AV:N/AC:L/Au:N/C:N/I:P/A:P
10.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | samsung | sth-eth-250_firmware | 0.20.17 | Yes |
Hardware | samsung | sth-eth-250 | - | No |