CVE-2017-16285 is a critical buffer overflow vulnerability affecting Insteon Hub firmware version 1012. Specifically, the PubNub message handler for the "cc" channel is susceptible to a stack-based buffer overflow when processing specially crafted commands. An attacker can exploit this by sending an authenticated HTTP request containing an oversized value for the 'offset' key, leading to arbitrary data overwrites. This vulnerability carries a CVSS score of 9.9 (CRITICAL), indicating a high-impact threat with network accessibility and low attack complexity, potentially resulting in complete compromise of confidentiality, integrity, and availability. While the EPSS score is low, the FAUCET Risk Score is high at 80/100. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The vulnerability has also received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1012CPE matchmatch criteria | cpe:2.3:o:insteon:hub_firmware:1012:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.