CVE-2021-25406

MEDIUM

Gear S Plugin <2.2.05.20122441 - Info Disclosure

Title source: llm
STIX 2.1

Description

Information exposure vulnerability in Gear S Plugin prior to version 2.2.05.20122441 allows unstrusted applications to access connected BT device information.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0008
EPSS Percentile 23.6%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-863 CWE-922
Status published
Products (1)
samsung/gear_s < 2.2.05.20122441
Published Jun 11, 2021
Tracked Since Feb 18, 2026