CVE-2021-25374
HIGHSamsung Members <3.9.00.9 - Auth Bypass
Title source: llmDescription
An improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink in versions 2.4.83.9 in Android O(8.1) and below, and 3.9.00.9 in Android P(9.0) and above allows remote attackers to access a user data related with Samsung Account.
Exploits (3)
nomisec
WORKING POC
27 stars
by ReversecLabs · poc
https://github.com/ReversecLabs/CVE-2021-25374_Samsung-Account-Access
Scores
CVSS v3
8.6
EPSS
0.0764
EPSS Percentile
91.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Details
CWE
CWE-285
Status
published
Products (1)
samsung/members
< 2.4.83.9
Published
Apr 09, 2021
Tracked Since
Feb 18, 2026