CVE-2025-26781

HIGH

Samsung Exynos and Modem Firmware - Denial of Service in L2 RLC AM PDU Handling

Title source: llm
STIX 2.1

Description

An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 9110, W920, W930, Modem 5123, and Modem 5300. Incorrect handling of RLC AM PDUs leads to a Denial of Service.

Scores

CVSS v3 7.5
EPSS 0.0015
EPSS Percentile 34.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-119 CWE-20
Status published
Products (13)
samsung/exynos_1080_firmware
samsung/exynos_1330_firmware
samsung/exynos_1380_firmware
samsung/exynos_1480_firmware
samsung/exynos_2200_firmware
samsung/exynos_850_firmware
samsung/exynos_9110_firmware
samsung/exynos_980_firmware
samsung/exynos_990_firmware
samsung/exynos_w920_firmware
... and 3 more
Published Oct 20, 2025
Tracked Since Feb 18, 2026