CVE-2026-23792
Received Received - Intake

NR RRC Baseband Crash in Samsung Exynos Processors

Vulnerability report for CVE-2026-23792, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: MITRE

Description

An issue was discovered in NR RRC in Samsung Mobile Processor and Modem Exynos 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W1000, Modem 5300, Modem 5400, and Modem 5410. Incorrect handling of unauthenticated downlink RRC Setup messages can cause the baseband to crash.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 14 associated CPEs
Vendor Product Version / Range
samsung exynos_1080 *
samsung exynos_2100 *
samsung exynos_1280 *
samsung exynos_2200 *
samsung exynos_1330 *
samsung exynos_1380 *
samsung exynos_1480 *
samsung exynos_2400 *
samsung exynos_1580 *
samsung exynos_2500 *
samsung w1000 *
samsung modem_5300 *
samsung modem_5400 *
samsung modem_5410 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-346 The product does not properly verify that the source of data or communication is valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves incorrect handling of unauthenticated downlink RRC Setup messages in Samsung's NR RRC component. This can cause the baseband processor to crash, leading to potential denial of service in affected devices.

Detection Guidance

Detection requires monitoring for baseband crashes or unusual RRC message handling. Check system logs for baseband processor errors or unexpected reboots. Use network monitoring tools to inspect RRC Setup messages for unauthenticated sources. Commands may include checking modem logs via AT commands or using diagnostic tools provided by Samsung.

Impact Analysis

The vulnerability may cause your device's baseband to crash, resulting in loss of network connectivity or service disruption. This could affect calls, data, and other mobile network-dependent functions.

Compliance Impact

This vulnerability does not directly impact compliance with GDPR, HIPAA, or similar standards as it primarily causes baseband crashes without evidence of data exposure or unauthorized access. However, if the crash leads to service disruption in systems handling sensitive data, it could indirectly affect availability requirements under these regulations.

Mitigation Strategies

Apply security updates from Samsung for affected Exynos and modem chipsets. Monitor for baseband crashes and unauthorized RRC Setup messages. Disable NR RRC if not required or restrict network access to trusted sources.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-23792. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart