CVE-2018-3918: Samsung Sth-Eth-250 Firmware

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

An exploitable vulnerability exists in the remote servers of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The hubCore process listens on port 39500 and relays any unauthenticated messages to SmartThings' remote servers, which incorrectly handle camera IDs for the 'sync' operation, leading to arbitrary deletion of cameras. An attacker can send an HTTP request to trigger this vulnerability.

Affected products

  • Samsung Sth-Eth-250 Firmware: version 0.20.17 only

Published 2018-08-27. Last modified 2026-06-17.