Executive brief
A vulnerability has been identified in the cellular modem components of various Samsung Exynos processors used in mobile phones and wearable devices. An attacker could remotely send specially crafted cellular network packets to cause the device's modem to crash. This results in a loss of cellular connectivity and potentially impacts the overall stability of the device.
Technical details
A vulnerability exists in the Layer 2 (L2) processing component of several Samsung Exynos mobile and wearable processors, as well as standalone modems. The issue stems from the incorrect handling of LTE MAC packets that contain an excessive number of MAC Control Elements (CEs), leading to uncontrolled resource consumption or a logic error that triggers a baseband crash. This is a network-based attack that requires no user interaction or prior authentication. Successful exploitation results in a denial-of-service (DoS) condition for the cellular modem, and according to CISA-ADP scoring, may also have implications for data confidentiality.
Affected products
- Samsung Exynos 980
- Samsung Exynos 990
- Samsung Exynos 850
- Samsung Exynos 1080
- Samsung Exynos 2100
- Samsung Exynos 1280
- Samsung Exynos 2200
- Samsung Exynos 1330
- Samsung Exynos 1380
- Samsung Exynos 1480
- Samsung Exynos 2400
- Samsung Exynos 1580
- Samsung Exynos 2500
- Samsung Exynos 9110
- Samsung Exynos W920
- Samsung Exynos W930
- Samsung Exynos W1000
- Samsung Modem 5123
- Samsung Modem 5300
- Samsung Modem 5400
Timeline
- 2025-07-21: other: Reported date according to vendor advisory
- 2026-04-06: disclosed: Initial publication date