CVE-2025-27807
BaseFortify
Publication date: 2026-01-05
Last updated on: 2026-01-09
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| samsung | exynos_990_firmware | * |
| samsung | exynos_990 | * |
| samsung | exynos_980_firmware | * |
| samsung | exynos_980 | * |
| samsung | exynos_850_firmware | * |
| samsung | exynos_850 | * |
| samsung | exynos_1080_firmware | * |
| samsung | exynos_1080 | * |
| samsung | exynos_2100_firmware | * |
| samsung | exynos_2100 | * |
| samsung | exynos_1280_firmware | * |
| samsung | exynos_1280 | * |
| samsung | exynos_2200_firmware | * |
| samsung | exynos_2200 | * |
| samsung | exynos_1330_firmware | * |
| samsung | exynos_1330 | * |
| samsung | exynos_1380_firmware | * |
| samsung | exynos_1380 | * |
| samsung | exynos_1480_firmware | * |
| samsung | exynos_1480 | * |
| samsung | exynos_1580_firmware | * |
| samsung | exynos_1580 | * |
| samsung | exynos_2400_firmware | * |
| samsung | exynos_2400 | * |
| samsung | exynos_9110_firmware | * |
| samsung | exynos_9110 | * |
| samsung | exynos_w930_firmware | * |
| samsung | exynos_w930 | * |
| samsung | exynos_w920_firmware | * |
| samsung | exynos_w920 | * |
| samsung | exynos_w1000_firmware | * |
| samsung | exynos_w1000 | * |
| samsung | modem_5123_firmware | * |
| samsung | modem_5123 | * |
| samsung | modem_5300_firmware | * |
| samsung | modem_5300 | * |
| samsung | modem_5400_firmware | * |
| samsung | modem_5400 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-787 | The product writes data past the end, or before the beginning, of the intended buffer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
CVE-2025-27807 is a high-severity vulnerability in multiple Samsung Exynos processors and modems. It occurs in the NAS (Non-Access Stratum) component due to a missing length check, which allows out-of-bounds write operations via malformed NAS packets. This means attackers can write data beyond the intended buffer limits, potentially causing memory corruption and enabling further exploitation. [1]
How can this vulnerability impact me? :
This vulnerability can lead to memory corruption on affected Samsung Exynos processors and modems. An attacker exploiting this flaw could potentially execute arbitrary code, cause system crashes, or disrupt device functionality, which may compromise device security and stability. [1]