PT-2025-45020 · Samsung · Exynos 1280+17

Published

2025-11-04

·

Updated

2025-11-07

·

CVE-2025-54329

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Samsung Exynos 980 Samsung Exynos 990 Samsung Exynos 850 Samsung Exynos 2100 Samsung Exynos 1280 Samsung Exynos 2200 Samsung Exynos 1330 Samsung Exynos 1380 Samsung Exynos 1480 Samsung Exynos 2400 Samsung Exynos 1580 Samsung Exynos 2500 Samsung Exynos W920 Samsung Exynos W930 Samsung Exynos W1000 Samsung Modem 5123 Samsung Modem 5300 Samsung Modem 5400
Description An issue exists in the Network Access Stratum (NAS) component of Samsung Mobile Processor, Wearable Processor, and Modem Exynos processors. A function responsible for handling multiple-payload messages, including SMS messages, does not properly validate the size of the input data. This lack of bounds checking can result in a heap overflow.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-54329

Affected Products

Exynos 1280
Exynos 1330
Exynos 1380
Exynos 1480
Exynos 1580
Exynos 2100
Exynos 2200
Exynos 2400
Exynos 2500
Exynos 850
Exynos 980
Exynos 990
Exynos W1000
Exynos W920
Exynos W930
Modem 5123
Modem 5300
Modem 5400