Junglewise Threat Intelligence

CVE-2026-21051: Samsung Mobile Devices incorrect permissions in TencentWifiSecurity

CVE-2026-21051 · Severity: info · CVSS 5.1 · Published 2026-07-10

Vendors: Samsung.

Executive brief

A security vulnerability in Samsung mobile devices running Android 14, 15, and 16 could allow an unauthorized person with physical or local access to the device to modify specific WLAN security settings. Specifically, incorrect permissions allow for the reconfiguration of TencentWifiSecurity settings, which could potentially compromise the integrity of wireless network connections. This issue has been addressed in the July 2026 Security Maintenance Release.

Technical details

A vulnerability involving incorrect default permissions exists in the WLAN security component of Samsung mobile devices. The flaw allows a local attacker without elevated privileges to modify TencentWifiSecurity settings. The root cause is improper access control configuration within the WLAN security module. An attacker with local access could exploit this to alter security configurations, potentially impacting the confidentiality or integrity of network traffic. The issue affects devices running Android 14, 15, and 16 and is resolved in the SMR Jul-2026 Release 1 update.

Affected products

  • Samsung Mobile Devices (Android 14, 15, 16) Prior to SMR Jul-2026 Release 1

Timeline

  • 2026-07-10: advisory: Samsung published the security update details.
  • 2026-07-10: disclosed: CVE-2026-21051 was published to the NVD.

References