Cisco Discovers Vulnerability in Samsung Hub
Confirmation required after firmware update

Samsung SmartThings Hub Samsung SmartThings Hub is a smart hub that controls and monitors various Internet of Things (IoT) devices commonly installed in smart homes, such as smart plugs, LED lights, thermostats, and cameras.
The Smart Hub acts as a central controller that allows users to remotely control these devices using their smartphones. The firmware used in the SmartThings Hub is designed based on Linux, enabling interoperability with IoT devices that use various technologies such as Ethernet, Zigbee, Z-Wave, and Bluetooth.
Recently, Cisco Talos discovered several vulnerabilities within the firmware used by the SmartThings Hub. Cisco Talos responded by working with Samsung in accordance with a pre-coordinated disclosure policy to resolve the issues and ensure Samsung firmware updates were provided to customers affected by the vulnerability.
According to what has been identified, the attacker was able to execute OS commands and arbitrary code on devices infected with the relevant vulnerabilities, and as these devices usually handle sensitive information, it seems that the attacker was able to access the information and monitor and control the devices within the smart home, which could be used for the following unauthorized actions:
▲Unlocking smart locks controlled via SmartThings Hub, gaining physical access to the smart home; ▲Remote monitoring of residents using cameras placed within the smart home; ▲Disabling motion detectors used by home alarm systems; ▲Manipulating smart plugs and activating or deactivating other products that can be connected; ▲Controlling thermostats by unauthorized attackers; ▲Causing physical damage to devices and appliances connected to smart plugs deployed within the smart home.
As hub devices can be built in a variety of configurations, the above scenario may not represent all situations. Cisco Talos recommends that affected SmartThings hubs be updated to the latest firmware version to ensure that the above vulnerabilities are addressed.
Devices such as SmartThings Hub are built to provide users with more convenience and automated services, but this requires special attention to ensure the safe construction of these devices and to ensure prompt updates according to the manufacturer’s new firmware updates. Since hub devices can be built in various environments, a successful attack on the hub device can cause serious damage. Therefore, Talos recommends updating as soon as possible. Samsung automatically rolls out updates to their hub devices, so in most cases no manual intervention is required, but it is important to verify that the updated version has actually been applied to your device, ensuring it is no longer vulnerable.