CVE-2018-3918 describes an exploitable vulnerability in the Samsung SmartThings Hub STH-ETH-250 (firmware version 0.20.17). An attacker can send an unauthenticated HTTP request to the hub's port 39500, which then relays the message to SmartThings' remote servers. This misidentification of camera IDs during a 'sync' operation allows for the arbitrary deletion of cameras. Rated with a CVSS score of 7.5 (HIGH), this vulnerability is network-exploitable with low attack complexity and requires no user interaction or privileges. The primary impact is a high integrity loss, specifically the deletion of cameras, with no confidentiality or availability impact. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. The vulnerability has also received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.20.17CPE matchmatch criteria | cpe:2.3:o:samsung:sth-eth-250_firmware:0.20.17:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.