CVE-2018-16270
HIGHSamsung Galaxy Gear Firmware < RE2 - Unauthenticated Arbitrary File Write via hcidump Utility
Title source: llmDescription
Samsung Galaxy Gear series before build RE2 includes the hcidump utility with no privilege or permission restriction. This allows an unprivileged process to dump Bluetooth HCI packets to an arbitrary file path.
References (2)
Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://media.defcon.org/DEF%20CON%2026/DEF%20CON%2026%20presentations/Dongsung%20Kim%20and%20Hyoung%20Kee%20Choi%20-%20Updated/DEFCON-26-Dongsung-Kim-and-Hyoung-Kee-Choi-Your-Watch-Can-Watch-You-Updated.pdf
Exploit, Third Party Advisory x_refsource_misc
https://www.youtube.com/watch?v=3IdgBwbOT-g&feature=youtu.be
Scores
CVSS v3
7.5
EPSS
0.0036
EPSS Percentile
58.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-269
Status
published
Products (10)
samsung/galaxy_gear_firmware
< re2
samsung/gear_2_firmware
< re2
samsung/gear_fit_2_firmware
< re2
samsung/gear_fit_2_pro_firmware
< re2
samsung/gear_fit_firmware
< re2
samsung/gear_live_firmware
< re2
samsung/gear_s2_firmware
< re2
samsung/gear_s3_firmware
< re2
samsung/gear_s_firmware
< re2
samsung/gear_sport_firmware
< re2
Published
Jan 22, 2020
Tracked Since
Feb 18, 2026