First published: Thu Aug 05 2021(Updated: )
Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause arbitrary webpage loading in webview.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Smartthings Firmware | <1.7.67.25 | |
Samsung Smartthings |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Improper access control vulnerability in SmartThings allows untrusted apps to load arbitrary webpages in webview.
The severity of CVE-2021-25446 vulnerability is rated as medium with a CVSS score of 5.3.
SmartThings versions prior to 1.7.67.25 are affected by CVE-2021-25446 vulnerability.
To mitigate the CVE-2021-25446 vulnerability, update SmartThings to version 1.7.67.25 or later.