PT-2025-21184 · Samsung · Exynos 1280+18

Ali Ranjbar

+3

·

Published

2025-05-14

·

Updated

2025-08-09

·

CVE-2025-26784

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Samsung Mobile Processor, Wearable Processor, and Modem Exynos versions 980 through 9825 Samsung Mobile Processor, Wearable Processor, and Modem Exynos versions 990 Samsung Mobile Processor, Wearable Processor, and Modem Exynos versions 850 Samsung Mobile Processor, Wearable Processor, and Modem Exynos versions 1080 Samsung Mobile Processor, Wearable Processor, and Modem Exynos versions 2100 Samsung Mobile Processor, Wearable Processor, and Modem Exynos versions 1280 Samsung Mobile Processor, Wearable Processor, and Modem Exynos versions 2200 Samsung Mobile Processor, Wearable Processor, and Modem Exynos versions 1330 Samsung Mobile Processor, Wearable Processor, and Modem Exynos versions 1380 Samsung Mobile Processor, Wearable Processor, and Modem Exynos versions 1480 Samsung Mobile Processor, Wearable Processor, and Modem Exynos versions 2400 Samsung Mobile Processor, Wearable Processor, and Modem Exynos versions 9110 Samsung Mobile Processor, Wearable Processor, and Modem Exynos W920 Samsung Mobile Processor, Wearable Processor, and Modem Exynos W930 Samsung Mobile Processor, Wearable Processor, and Modem Exynos W1000 Samsung Mobile Processor, Wearable Processor, and Modem Modem 5123 Samsung Mobile Processor, Wearable Processor, and Modem Modem 5300 Samsung Mobile Processor, Wearable Processor, and Modem Modem 5400
Description: An issue was discovered in the NAS component of Samsung Mobile Processor, Wearable Processor, and Modem Exynos. The lack of a length check leads to out-of-bounds writes.
Recommendations: For Samsung Mobile Processor, Wearable Processor, and Modem Exynos versions 980 through 9825, consider disabling the NAS component until a patch is available. For Samsung Mobile Processor, Wearable Processor, and Modem Exynos versions 990, restrict access to the NAS component to minimize the risk of exploitation. For Samsung Mobile Processor, Wearable Processor, and Modem Exynos versions 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400, avoid using the NAS component in sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2025-26784

Affected Products

Exynos 1080
Exynos 1280
Exynos 1330
Exynos 1380
Exynos 1480
Exynos 2100
Exynos 2200
Exynos 2400
Exynos 850
Exynos 9110
Exynos 980
Exynos 9825
Exynos 990
Exynos W1000
Exynos W920
Exynos W930
Modem 5123
Modem 5300
Modem 5400