CVE-2021-25374

HIGH

Samsung Members <3.9.00.9 - Auth Bypass

Title source: llm

Description

An improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink in versions 2.4.83.9 in Android O(8.1) and below, and 3.9.00.9 in Android P(9.0) and above allows remote attackers to access a user data related with Samsung Account.

Exploits (3)

nomisec WORKING POC 27 stars
by ReversecLabs · poc
https://github.com/ReversecLabs/CVE-2021-25374_Samsung-Account-Access
inthewild WORKING POC
poc
https://github.com/withsecurelabs/cve-2021-25374_samsung-account-access
inthewild WORKING POC
poc
https://github.com/fsecurelabs/cve-2021-25374_samsung-account-access

Scores

CVSS v3 8.6
EPSS 0.0764
EPSS Percentile 91.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Details

CWE
CWE-285
Status published
Products (1)
samsung/members < 2.4.83.9
Published Apr 09, 2021
Tracked Since Feb 18, 2026