CVE-2025-48025

MEDIUM

Samsung Exynos Firmware - Improper Access Control in Log File

Title source: llm
STIX 2.1

Description

In Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000, there is an improper access control vulnerability related to a log file.

Scores

CVSS v3 4.3
EPSS 0.0004
EPSS Percentile 12.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (10)
samsung/exynos_1280_firmware
samsung/exynos_1330_firmware
samsung/exynos_1380_firmware
samsung/exynos_1480_firmware
samsung/exynos_1580_firmware
samsung/exynos_850_firmware
samsung/exynos_980_firmware
samsung/exynos_w1000_firmware
samsung/exynos_w920_firmware
samsung/exynos_w930_firmware
Published Oct 20, 2025
Tracked Since Feb 18, 2026