CVE-2017-16261 describes multiple exploitable stack-based buffer overflow vulnerabilities in the Insteon Hub firmware version 1012, specifically within the PubNub message handler for the "cc" channel. An authenticated attacker can trigger this by sending specially crafted commands via the PubNub service, leading to arbitrary data overwrites. With a CVSS score of 8.8 (High), this vulnerability allows for high impact to confidentiality, integrity, and availability with low attack complexity and requires only low privileges. While no active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion has been observed, the FAUCET Risk Score of 70/100 indicates a notable risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1012CPE matchmatch criteria | cpe:2.3:o:insteon:hub_firmware:1012:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.