CVE-2018-3907: Critical severity Samsung STH-ETH-250 Firmware vulnerability
An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly handles pipelined HTTP requests, which allows successive requests to overwrite the previously parsed HTTP method, 'onurl' callback. An attacker can send an HTTP request to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-3907?
CVE-2018-3907 has been classified as a high-severity vulnerability due to its impact on the HTTP server of the Samsung SmartThings Hub.
How do I fix CVE-2018-3907?
To fix CVE-2018-3907, upgrade the Samsung SmartThings Hub firmware to a version higher than 0.20.17.
What systems are affected by CVE-2018-3907?
CVE-2018-3907 specifically affects the Samsung SmartThings Hub STH-ETH-250 running firmware version 0.20.17.
What type of vulnerability is CVE-2018-3907?
CVE-2018-3907 is a vulnerability related to HTTP request handling in the REST parser of the video-core process.
Can CVE-2018-3907 be exploited remotely?
Yes, CVE-2018-3907 can be exploited remotely through pipelined HTTP requests to the vulnerable server.