← Back to browse · API

CVE-2018-3895

Severity
CRITICAL
CVSS
9.9
EPSS
0.01804
Risk score
40.23
CISA KEV
No
PoC
No
Published
2018-08-28
Modified
2024-09-17
First seen
2026-08-07
Aliases
EUVD-2018-15681, GHSA-624G-XQW5-CCP4
Products
Samsung:Samsung Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17
Sources
euvd EUVD-2018-15681

Description

An exploitable buffer overflow vulnerability exists in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 Firmware version 0.20.17. The strncpy call overflows the destination buffer, which has a size of 52 bytes. An attacker can send an arbitrarily long 'endTime' value in order to exploit this vulnerability. An attacker can send an HTTP request to trigger this vulnerability.

References