CVE-2020-25048

MEDIUM

Samsung Android Q with ONEUI 2.1 - Unauthenticated File Injection via Quick Share

Title source: llm
STIX 2.1

Description

An issue was discovered on Samsung mobile devices with Q(10.0) (with ONEUI 2.1) software. In the Lockscreen state, the Quick Share feature allows unauthenticated downloads, aka file injection. The Samsung ID is SVE-2020-17760 (August 2020).

References (1)

Core 1
Core References

Scores

CVSS v3 4.6
EPSS 0.0017
EPSS Percentile 6.7%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-306
Status published
Products (1)
google/android 10.0
Published Aug 31, 2020
Tracked Since Feb 18, 2026