Back

CVE-2017-16338

CRITICAL

An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware version 1012. At 0x9d01bad0 the value for the host key is copied using strcpy to the buffer at 0xa00016e0. This buffer is 32 bytes large, sending anything longer will cause a buffer overflow.

Published: Aug 2, 2018 Modified: Jun 17, 2026
CWE-120

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: LOW User Interaction: NONE Scope: CHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
insteon hub_firmware 1012

GitHub Security Advisory GHSA-x388-mxc3-gqf6

An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub...

Risk Scores

CVSS Score 9.9 / 10
EPSS Score 1.36%

Top 31% most likely to be exploited

Threat Score 40 / 100

Data Sources

NVD EPSS GitHub