CVE-2018-3909: Critical severity samsung sth-eth-250 vulnerability
An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly handles pipelined HTTP requests, which allows successive requests to overwrite the previously parsed HTTP method, 'onmessagecomplete' callback. An attacker can send an HTTP request to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-3909?
CVE-2018-3909 is rated as high severity due to the risk of exploitation through HTTP request manipulation.
How do I fix CVE-2018-3909?
To fix CVE-2018-3909, update the Samsung SmartThings Hub to a firmware version higher than 0.20.17.
What systems are affected by CVE-2018-3909?
CVE-2018-3909 affects the Samsung SmartThings Hub model STH-ETH-250 running firmware version 0.20.17.
What type of vulnerability is CVE-2018-3909?
CVE-2018-3909 is a REST parser vulnerability in the video-core HTTP server that can lead to improper request handling.
Can CVE-2018-3909 be exploited remotely?
Yes, CVE-2018-3909 can be exploited remotely through crafted HTTP requests sent to the vulnerable SmartThings Hub.