CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-52908

CVSS 9.8v3.1pub. 2026-04-07upd. 2026-04-09

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000. Incorrect Handling of the NL80211 vendor command leads to a buffer overflow via a certain ioctl message, issue 1 of 2.

🤖 AI Analysis
How it works

The error results from improper handling of the NL80211 vendor command in the Wi-Fi driver. Through a specially crafted ioctl message, a buffer overflow (buffer overflow) in the kernel space is possible. An attacker can deliver a malicious payload through the Wi-Fi network interface without needing device access or user interaction. This is the first of two identified vulnerabilities of this type in this component.

Impact

An attacker can gain full control over the device, including the ability to read and modify data (RCE, privilege escalation) and cause device unavailability. The compromise occurs at the kernel driver level, which provides access to system-protected resources.

Mitigation & patch

Patches available from the manufacturer should be applied in accordance with the references: https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-52908/. Until an update is available, it is recommended to restrict device exposure to untrusted Wi-Fi networks.

Who is affected

Samsung Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000 processors — mobile and wearable devices equipped with the firmware of these processors

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Samsung Exynos 1280

    HW
    Samsung
    all versions
  • Samsung Exynos 1280 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 1330

    HW
    Samsung
    all versions
  • Samsung Exynos 1330 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 1380

    HW
    Samsung
    all versions
  • Samsung Exynos 1380 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 1480

    HW
    Samsung
    all versions
  • Samsung Exynos 1480 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 1580

    HW
    Samsung
    all versions
  • Samsung Exynos 1580 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 850

    HW
    Samsung
    all versions
  • Samsung Exynos 850 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 980

    HW
    Samsung
    all versions
  • Samsung Exynos 980 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos W1000

    HW
    Samsung
    all versions
  • Samsung Exynos W1000 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos W920

    HW
    Samsung
    all versions
  • Samsung Exynos W920 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos W930

    HW
    Samsung
    all versions
  • Samsung Exynos W930 Firmware

    OS
    Samsung
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2025-52909CRITICAL9.8PL ✓same product

Buffer overflow w sterowniku Wi-Fi Samsung Exynos przez NL80211

CVE-2025-62818CRITICAL9.8PL ✓same product

Out-of-bounds write w procesorach Samsung Exynos przy przetwarzaniu SMS TP-UD

CVE-2025-54328CRITICAL10.0PL ✓same product

Stack-based Buffer Overflow w obsłudze SMS w procesorach Samsung Exynos

CVE-2025-58349CRITICAL9.1PL ✓same product

Błąd obsługi pakietów LTE MAC w procesorach Samsung Exynos powoduje crash baseband

CVE-2025-27807CRITICAL9.1PL ✓same product

Out-of-bounds write w Samsung Exynos via błędne pakiety NAS