CVE-2025-26783

HIGH

Samsung Exynos Modem DoS via RRC Undefined Value Handling

Title source: llm
STIX 2.1

Description

An issue was discovered in RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 2100, 1280, 2200, 1330, 1380, 1480, 2400, W1000, Modem 5300, and Modem 5400. Incorrect handling of undefined values leads to a Denial of Service.

Scores

CVSS v3 7.5
EPSS 0.0042
EPSS Percentile 62.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (10)
samsung/exynos_1280_firmware
samsung/exynos_1330_firmware
samsung/exynos_1380_firmware
samsung/exynos_1480_firmware
samsung/exynos_2100_firmware
samsung/exynos_2200_firmware
samsung/exynos_2400_firmware
samsung/exynos_modem_5300_firmware
samsung/exynos_modem_5400_firmware
samsung/exynos_w1000_firmware
Published May 14, 2025
Tracked Since Feb 18, 2026