Samsung SmartThings Improper Verification of Cryptographic Signature Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Samsung SmartThings. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Hub Local API service, which listens on TCP port 8766 by default. The issue results from the lack of proper verification of a cryptographic signature. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-25615.
History

Tue, 11 Mar 2025 22:45:00 +0000

Type Values Removed Values Added
Description Samsung SmartThings Improper Verification of Cryptographic Signature Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Samsung SmartThings. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Hub Local API service, which listens on TCP port 8766 by default. The issue results from the lack of proper verification of a cryptographic signature. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-25615.
Title Samsung SmartThings Improper Verification of Cryptographic Signature Authentication Bypass Vulnerability
Weaknesses CWE-347
References
Metrics cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published: 2025-03-11T22:30:44.003Z

Updated: 2025-03-11T22:30:44.003Z

Reserved: 2025-03-11T22:30:02.709Z

Link: CVE-2025-2233

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-03-11T23:15:38.610

Modified: 2025-03-11T23:15:38.610

Link: CVE-2025-2233

cve-icon Redhat

No data.