CVE-2025-26782
BaseFortify
Publication date: 2025-10-20
Last updated on: 2025-10-28
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| samsung | exynos_w920_firmware | * |
| samsung | exynos_w920 | * |
| samsung | exynos_1080_firmware | * |
| samsung | exynos_1080 | * |
| samsung | exynos_980_firmware | * |
| samsung | exynos_980 | * |
| samsung | exynos_990_firmware | * |
| samsung | exynos_990 | * |
| samsung | exynos_850_firmware | * |
| samsung | exynos_850 | * |
| samsung | exynos_2200_firmware | * |
| samsung | exynos_2200 | * |
| samsung | exynos_1330_firmware | * |
| samsung | exynos_1330 | * |
| samsung | exynos_1380_firmware | * |
| samsung | exynos_1380 | * |
| samsung | exynos_1480_firmware | * |
| samsung | exynos_1480 | * |
| samsung | exynos_9110_firmware | * |
| samsung | exynos_9110 | * |
| samsung | modem_5400_firmware | * |
| samsung | modem_5400 | * |
| samsung | modem_5123_firmware | * |
| samsung | modem_5123 | * |
| samsung | exynos_w930_firmware | * |
| samsung | exynos_w930 | * |
| samsung | exynos_1280_firmware | * |
| samsung | exynos_1280 | * |
| samsung | exynos_2100_firmware | * |
| samsung | exynos_2100 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-400 | The product does not properly control the allocation and maintenance of a limited resource. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
CVE-2025-26782 is a vulnerability in multiple Samsung Exynos processors and modems caused by incorrect handling of Radio Link Control (RLC) Acknowledged Mode (AM) Protocol Data Units (PDUs) within the Layer 2 (L2) component. This improper processing can lead to a Denial of Service (DoS) condition. [1]
How can this vulnerability impact me? :
This vulnerability can cause a Denial of Service (DoS) on affected Samsung Exynos processors and modems, potentially disrupting device functionality or connectivity by making the device unable to properly handle certain network communications. [1]