CVE-2025-20895

LOW

Samsung Galaxy Store < 4.5.87.6 - Authentication Bypass via Alternate Path

Title source: llm
STIX 2.1

Description

Authentication Bypass Using an Alternate Path in Galaxy Store prior to version 4.5.87.6 allows physical attackers to install arbitrary applications to bypass restrictions of Setupwizard.

References (1)

Core 1

Scores

CVSS v3 3.2
EPSS 0.0004
EPSS Percentile 11.2%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (1)
samsung/galaxy_store < 4.5.87.6
Published Feb 04, 2025
Tracked Since Feb 18, 2026