GHSA-7373-q85p-xf23
GitHub Security Advisory
⚠ Unreviewed
HIGH
Has CVE
Advisory Details
An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The strcpy call overflows the destination buffer, which has a size of 2000 bytes. An attacker can send an arbitrarily long "sessionToken" value in order to exploit this vulnerability.
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: November 23, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.