CVE-2017-16259 is a critical buffer overflow vulnerability affecting Insteon Hub firmware version 1012. Specifically, the PubNub message handler for the "cc" channel is susceptible to specially crafted commands that can lead to a stack-based buffer overflow, allowing arbitrary data overwrites. This vulnerability has a CVSS score of 9.9 (CRITICAL) due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While an attacker needs to send an authenticated HTTP request, the potential for complete system compromise is significant. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or notable community discussion or media coverage for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1012CPE matchmatch criteria | cpe:2.3:o:insteon:hub_firmware:1012:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.