CVE-2025-20895
LOWSamsung Galaxy Store < 4.5.87.6 - Authentication Bypass via Alternate Path
Title source: llmDescription
Authentication Bypass Using an Alternate Path in Galaxy Store prior to version 4.5.87.6 allows physical attackers to install arbitrary applications to bypass restrictions of Setupwizard.
References (1)
Core 1
Core References
Scores
CVSS v3
3.2
EPSS
0.0004
EPSS Percentile
11.2%
Attack Vector
PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
Status
published
Products (1)
samsung/galaxy_store
< 4.5.87.6
Published
Feb 04, 2025
Tracked Since
Feb 18, 2026