CVE-2026-21005

MEDIUM

Samsung Mobile Smart Switch < 3.7.69.15 - Path Traversal and Arbitrary File Write

Title source: llm
STIX 2.1

Description

Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Smart Switch privilege.

Scores

CVSS v3 6.5
EPSS 0.0024
EPSS Percentile 14.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
samsung/smart_switch < 3.7.69.15
Samsung Mobile/Smart Switch 3.7.69.15
Published Mar 16, 2026
Tracked Since Mar 16, 2026