Samsung · Samsung Smartthings Hub · CVE-2025-2233
Name of the Vulnerable Software and Affected Versions:
Samsung SmartThings (affected versions not specified)
Description:
This issue allows network-adjacent attackers to bypass authentication on affected installations of Samsung SmartThings, with no authentication required for exploitation. The flaw exists within the Hub Local API service, which listens on TCP port 8766 by default, due to the lack of proper verification of a `cryptographic signature`. An attacker can leverage this to bypass authentication on the system.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.