CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-27807

CVSS 9.1v3.1pub. 2026-01-05upd. 2026-01-09

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The lack of a length check leads to out-of-bounds writes via malformed NAS packets.

🤖 AI Analysis
How it works

Lack of data length verification during processing of NAS (Non-Access Stratum) layer packets in the modem part of Exynos chipsets leads to writing data outside the intended memory area (out-of-bounds write). An attacker can send a maliciously crafted NAS packet over the cellular network without any authentication, causing buffer overflow and potential overwriting of critical structures in device memory.

Impact

An attacker can cause disclosure of sensitive data (confidentiality breach) and trigger denial of service or device failure (availability breach). Due to the network attack vector without required privileges, this vulnerability is particularly dangerous in mobile environments.

Mitigation & patch

Security patches available from the manufacturer should be applied according to references — security updates published by Samsung Semiconductor are available at: https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-27807/

Who is affected

Firmware of Samsung Exynos processors and modems: 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400 — used in Samsung mobile devices and wearables.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
  • Samsung Exynos 1080

    HW
    Samsung
    all versions
  • Samsung Exynos 1080 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 1280

    HW
    Samsung
    all versions
  • Samsung Exynos 1280 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 1330

    HW
    Samsung
    all versions
  • Samsung Exynos 1330 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 1380

    HW
    Samsung
    all versions
  • Samsung Exynos 1380 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 1480

    HW
    Samsung
    all versions
  • Samsung Exynos 1480 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 1580

    HW
    Samsung
    all versions
  • Samsung Exynos 1580 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 2100

    HW
    Samsung
    all versions
  • Samsung Exynos 2100 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 2200

    HW
    Samsung
    all versions
  • Samsung Exynos 2200 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 2400

    HW
    Samsung
    all versions
  • Samsung Exynos 2400 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 850

    HW
    Samsung
    all versions
  • Samsung Exynos 850 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 9110

    HW
    Samsung
    all versions
  • Samsung Exynos 9110 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 980

    HW
    Samsung
    all versions
  • Samsung Exynos 980 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 990

    HW
    Samsung
    all versions
  • Samsung Exynos 990 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos W1000

    HW
    Samsung
    all versions
  • Samsung Exynos W1000 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos W920

    HW
    Samsung
    all versions
  • Samsung Exynos W920 Firmware

    OS
    Samsung
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2025-62818CRITICAL9.8PL ✓same product

Out-of-bounds write w procesorach Samsung Exynos przy przetwarzaniu SMS TP-UD

CVE-2025-52909CRITICAL9.8PL ✓same product

Buffer overflow w sterowniku Wi-Fi Samsung Exynos przez NL80211

CVE-2025-52908CRITICAL9.8PL ✓same product

Buffer overflow w sterowniku Wi-Fi Samsung Exynos przez błędną obsługę NL80211

CVE-2025-54328CRITICAL10.0PL ✓same product

Stack-based Buffer Overflow w obsłudze SMS w procesorach Samsung Exynos

CVE-2025-58349CRITICAL9.1PL ✓same product

Błąd obsługi pakietów LTE MAC w procesorach Samsung Exynos powoduje crash baseband