Skip to main content

Samsung Smartcam has a critical remote execution vulnerability, update coming

Critical remote execution vulnerability, firmware update coming to Samsung smartcam

Securing a PC is hard enough, with an entire industry of security software vendors working to make your PC safe and companies like Microsoft making security a primary focus. There are many other pieces of the technology puzzle today where security seems to be taking a back seat, and they are all connected to the same risky internet.

One of the most vulnerable members of the Internet of Things (IoT) seems to be the humble webcam, which by its very nature can open you up to privacy concerns and that can be used to host botnets for distributed denial-of-service (DDoS) attacks. Recently, one model in Samsung’s Smartcam line of webcams has been identified as having a serious vulnerability, PCWorld reports.

Recommended Videos

Samsung’s Smartcam is quite popular, offering a relatively simple device with easy setup and configuration using smartphone apps and the company’s My Smartcam cloud service. The move away from using an onboard web service for configuration was a decision made by the webcam’s original developer, Samsung Techwin, based on vulnerabilities identified in the web-based management interface.

In response, the Smartcam SNH-1011’s local web-based management portal was disabled, leaving only the apps and online service. While that was a logical response, there was only one problem with its implementation — while the administrative access was disabled, the web server was left running and actively utilized for a variety of functionality. For example, PHP scripts used in the iWatch video monitoring system were left alone.

It’s this PHP code that created the recently identified vulnerability discovered by “hacking collective” the Exploiteers. According to researchers from that organization, “The iWatch Install.php vulnerability can be exploited by crafting a special filename which is then stored within a tar command passed to a PHP system() call. Because the web-server runs as root, the filename is user supplied, and the input is used without sanitization, we are able to inject our own commands within to achieve root remote command execution.”

Samsung Smartcam iWatch Root Exploit

Samsung has reached out with a statement clarifying the situation: “It was recently discovered that the Samsung Smartcam SNH-1011 security cameras contain a code execution vulnerability that could allow hackers to gain root access and take full control of them. Upon further inspection, the web server running on this device hosted a PHP script related to a third-party service. This vulnerability only affects the SNH-1011 model and will be removed in an upcoming firmware update. As a result, we are taking every precaution to prevent additional issues with products in the SmartCam line. As a reminder, it is best practice for consumers to ensure their home networks are protected with passwords that are complex and regularly updated.”

That limits the situation a bit to only a single Smartcam model. If you’re using the SNH-1011, then you might want to turn it off until Samsung issues the promised firmware update.

This story was originally published in January 2017. Updated on 01-18-2017 by Mark Coppock: Added official Samsung statement.

Mark Coppock
Mark Coppock is a Freelance Writer at Digital Trends covering primarily laptop and other computing technologies. He has…
This Alienware Aurora gaming PC with RTX 5080 is $700 off
Alienware Aurora R16 sitting on a coffee table.

Gamers who are planning to make a huge investment in gaming PC deals should still be on the lookout for opportunities at savings. Dell has an offer that is hard to refuse: a $700 discount on the Alienware Aurora R16 ACT1250 gaming desktop with the Nvidia GeForce RTX 5080 graphics card, bringing its price down to $3,050 from $3,750 originally. It's still expensive, but you might as well take advantage of the lowered price if you're already thinking about spending this much on your PC gaming setup with a 50-series GPU.

Why you should buy the Alienware Aurora R16 ACT1250 gaming PC

Read more
Here’s your chance to buy the Apple MacBook Air M3 for less than $1,000
The MacBook Air on a table in front of a window.

For Apple fans who have been on the lookout for MacBook deals: We've found an interesting one from B&H Photo Video. The 13-inch model of the Apple MacBook Air M3 with 8GB of RAM and a 512GB SSD is on sale for only $899, for savings of $400 on the laptop's original price of $1,299. That's a huge discount that you probably won't find anywhere else, but you'll need to act fast if you're interested in taking advantage of this bargain because it may disappear as soon as tomorrow.

Why you should buy the Apple MacBook Air M3

Read more
The Samsung Odyssey G8 gaming monitor is a steal with this deal
Uncharted Legacy of Thieves collection running on Samsung Odyssey Neo G8.

If your dream PC gaming setup is still missing a screen, we highly recommend taking a look at Samsung monitor deals for nice bargains. Here's one that's available right now: the 32-inch Samsung Odyssey Neo G8 gaming monitor with a $550 discount, which almost halves its original price of $1,300 to only $750. You shouldn't be wasting time though, as the offer may disappear at any moment -- you're going to have to proceed with your purchase immediately in order to secure the savings.

Why you should buy the 32-inch Samsung Odyssey Neo G8 gaming monitor

Read more