CVE-2004-2626

Siemens S55 - Unauthenticated SMS Spoofing via GUI Overlay

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-2626. PoCs published by FtR.

AI-analyzed exploit summary This exploit demonstrates a race condition vulnerability in Siemens S55 phones, allowing SMS messages to be sent without user confirmation. The PoC uses the Siemens-specific SMS API to send an SMS in the background while displaying distracting UI elements.

Description

GUI overlay vulnerability in the Java API in Siemens S55 cellular phones allows remote attackers to send unauthorized SMS messages by overlaying a confirmation message with a malicious message.

Exploits (1)

exploitdb WORKING POC VERIFIED
by FtR · javaremotehardware
https://www.exploit-db.com/exploits/24065

This exploit demonstrates a race condition vulnerability in Siemens S55 phones, allowing SMS messages to be sent without user confirmation. The PoC uses the Siemens-specific SMS API to send an SMS in the background while displaying distracting UI elements.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Racy
Target: Siemens S55 (and potentially other Siemens mobile phones with similar firmware)
No auth needed
Prerequisites: Physical or remote installation of the malicious MIDlet on the target device · Target device must be a vulnerable Siemens model
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10227
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/5703
Mailing List mailing-list x_refsource_fulldisc
http://marc.info/?l=full-disclosure&m=108308895624565&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/15995
Mailing List mailing-list x_refsource_fulldisc
http://marc.info/?l=full-disclosure&m=108325033624812&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/alerts/2004/Apr/1009959.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11492

Scores

EPSS 0.0342
EPSS Percentile 87.4%

Details

Status published
Products (1)
siemens/s55 09.2179
Published Dec 31, 2004
Tracked Since Feb 18, 2026