Back
CVE-2017-16338
CRITICAL
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware version 1012. At 0x9d01bad0 the value for the host key is copied using strcpy to the buffer at 0xa00016e0. This buffer is 32 bytes large, sending anything longer will cause a buffer overflow.
Published: Aug 2, 2018
Modified: Jun 17, 2026
CWE-120
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| insteon | hub_firmware | 1012 |
GitHub Security Advisory GHSA-x388-mxc3-gqf6
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub...
References (2)
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0484 Exploit, Third Party Advisory
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0484 Exploit, Third Party Advisory
Risk Scores
CVSS Score
9.9 / 10
EPSS Score
1.36%
Top 31% most likely to be exploited
Threat Score
40 / 100
Data Sources
NVD
EPSS
GitHub