PT-2026-1320 · Samsung · Modem 5400+18

Published

2026-01-05

·

Updated

2026-01-29

·

CVE-2025-27807

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980 Samsung Mobile Processor, Wearable Processor, and Modem Exynos 990 Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850 Samsung Mobile Processor, Wearable Processor, and Modem Exynos 1080 Samsung Mobile Processor, Wearable Processor, and Modem Exynos 2100 Samsung Mobile Processor, Wearable Processor, and Modem Exynos 1280 Samsung Mobile Processor, Wearable Processor, and Modem Exynos 2200 Samsung Mobile Processor, Wearable Processor, and Modem Exynos 1330 Samsung Mobile Processor, Wearable Processor, and Modem Exynos 1380 Samsung Mobile Processor, Wearable Processor, and Modem Exynos 1480 Samsung Mobile Processor, Wearable Processor, and Modem Exynos 2400 Samsung Mobile Processor, Wearable Processor, and Modem Exynos 1580 Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9110 Samsung Mobile Processor, Wearable Processor, and Modem W920 Samsung Mobile Processor, Wearable Processor, and Modem W930 Samsung Mobile Processor, Wearable Processor, and Modem W1000 Samsung Modem 5123 Samsung Modem 5300 Samsung Modem 5400
Description The software suffers from a flaw due to the absence of a length check, which can result in out-of-bounds writes when processing malformed NAS packets.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2025-27807

Affected Products

Exynos 1080
Exynos 1280
Exynos 1330
Exynos 1380
Exynos 1480
Exynos 1580
Exynos 2100
Exynos 2200
Exynos 2400
Exynos 850
Exynos 9110
Exynos 980
Exynos 990
Modem 5123
Modem 5300
Modem 5400
W1000
W920
W930