CVE-2026-33960
Received Received - Intake

Wi-Fi Driver Out-of-Bounds Write in Samsung Exynos Processors

Vulnerability report for CVE-2026-33960, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: MITRE

Description

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 1580, 1680, W920, W930, and W1000. . A malformed ioctl command to the Wi-Fi interface device can lead to improper buffer size allocation, resulting in an out-of-bounds write and causing a denial of service (DoS).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
samsung exynos_1330 *
samsung exynos_1380 *
samsung exynos_1480 *
samsung exynos_1580 *
samsung exynos_1680 *
samsung w920 *
samsung w930 *
samsung w1000 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-33960 is a vulnerability in Samsung Exynos and W-series processors where a malformed command sent to the Wi-Fi interface can cause improper memory allocation. This leads to an out-of-bounds write, potentially causing a denial of service (DoS) by disrupting system operations.

Detection Guidance

Detection of this vulnerability requires checking for malformed ioctl commands sent to the Wi-Fi interface device on affected Samsung processors. Monitor system logs for unusual Wi-Fi driver errors or crashes. Check for out-of-bounds write events in kernel logs. Use tools like 'dmesg' to inspect kernel messages for Wi-Fi-related anomalies.

Impact Analysis

This vulnerability could cause your device to crash or become unresponsive if an attacker sends a malformed Wi-Fi command. It may lead to temporary service interruptions but does not appear to allow data theft or unauthorized access based on available information.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by causing service disruptions or data processing interruptions due to denial of service conditions. However, the provided context does not explicitly detail compliance implications or data exposure risks.

Mitigation Strategies

Apply the latest security updates from Samsung Semiconductor for affected Exynos and W-series processors. Disable Wi-Fi interface access if not required and monitor for unusual activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-33960. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart