Junglewise Threat Intelligence

CVE-2021-25489: Samsung Mobile Devices Improper Input Validation Vulnerability

CVE-2021-25489 · Severity: critical · CVSS 5.5 · Exploited in the wild · Published 2023-06-29

Technologies: Samsung Mobile Devices. Vendors: Samsung.

Executive brief

Samsung mobile devices contain an improper input validation vulnerability in the modem interface driver. This flaw results in a format string bug that can be triggered if radio permission is gained, leading to a kernel panic and denial of service.

Affected products

  • Samsung Android Prior to SMR Oct-2021 Release 1 (Versions 8.1, 9.0, 10.0, 11.0)

Timeline

  • 2021-10-06: disclosed: NVD Published Date
  • 2021-10-01: patched: SMR Oct-2021 Release 1
  • 2023-06-29: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats