CVE-2021-25447
Published Aug 5, 2021Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause local file inclusion in webview.
Vendor/product archive
3 CVEs tagged to samsung / smartthings_firmware — 0 Critical, 0 High, 2 Medium, 1 Low, 0 Unrated.
Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause local file inclusion in webview.
Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause arbitrary webpage loading in webview.
Information Exposure vulnerability in SmartThings prior to version 1.7.64.21 allows attacker to access user information via log.