CVE-2018-3856 is a critical command injection vulnerability in the RTSP configuration of the Samsung SmartThings Hub STH-ETH-250 (firmware version 0.20.17). The flaw stems from improper handling of spaces in the URL field, allowing an authenticated attacker to inject arbitrary operating system commands by sending crafted HTTP requests. With a CVSS score of 9.9, this vulnerability presents a critical risk, enabling complete compromise of confidentiality, integrity, and availability of the affected device. While no public exploit intelligence (Metasploit, Nuclei, ExploitDB) or KEV catalog listing exists, and community discussion is minimal, the high severity warrants immediate attention for affected systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.20.17CPE matchmatch criteria | cpe:2.3:o:samsung:sth-eth-250_firmware:0.20.17:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.