CVE-2025-57834
Denial of Service in Samsung Exynos Processors via Input Validation Flaw
Publication date: 2026-04-06
Last updated on: 2026-04-07
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| samsung | exynos_980_firmware | * |
| samsung | exynos_990_firmware | * |
| samsung | exynos_850_firmware | * |
| samsung | exynos_1080_firmware | * |
| samsung | exynos_2100_firmware | * |
| samsung | exynos_1280_firmware | * |
| samsung | exynos_1330_firmware | * |
| samsung | exynos_1380_firmware | * |
| samsung | exynos_1480_firmware | * |
| samsung | exynos_1580_firmware | * |
| samsung | exynos_2200_firmware | * |
| samsung | exynos_2400_firmware | * |
| samsung | exynos_2500_firmware | * |
| samsung | exynos_9110_firmware | * |
| samsung | exynos_w930_firmware | * |
| samsung | exynos_w920_firmware | * |
| samsung | exynos_w1000_firmware | * |
| samsung | exynos_modem_5123_firmware | * |
| samsung | exynos_modem_5300_firmware | * |
| samsung | exynos_modem_5400_firmware | * |
| samsung | exynos_1680_firmware | * |
| samsung | exynos_modem_5410_firmware | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-20 | The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in various Samsung processors and modems, including the Exynos 980, 850, 990, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 1680, 9110, W920, W930, W1000, and Modem models 5123, 5300, 5400, and 5410.
The issue is caused by the absence of proper input validation, which leads to a Denial of Service (DoS) condition.
How can this vulnerability impact me? :
The vulnerability can cause a Denial of Service (DoS) on affected Samsung processors and modems.
This means that the affected device or component could become unavailable or unresponsive due to improper handling of input data.
The CVSS base score of 7.5 indicates a high severity impact on availability, but no impact on confidentiality or integrity.