CVE-2017-16345 describes a critical buffer overflow vulnerability in Insteon Hub firmware version 1012, allowing an authenticated attacker to execute arbitrary code. The vulnerability stems from an unbounded strcpy operation when processing the 's_port' key in an HTTP request, leading to a buffer overflow on a 6-byte buffer. With a CVSS score of 9.9 (CRITICAL), this flaw presents a high risk of complete compromise (Confidentiality, Integrity, Availability) with low attack complexity and no user interaction required. While no public exploits (Metasploit, Nuclei, ExploitDB) or active exploitation (KEV) have been identified, and community discussion is minimal, the high FAUCET Risk Score of 80/100 indicates its significant potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1012CPE matchmatch criteria | cpe:2.3:o:insteon:hub_firmware:1012:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.