Samsung vendor intelligence
Samsung Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Samsung products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 17
- Known exploited vulnerabilities affecting Samsung products
- In CISA KEV
- 16
- Records also listed in the official catalog
- Beyond CISA KEV
- 1
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- Samsung KEVs with sensor-observed exploitation activity
The catalog gap matters for Samsung exposure
One of the seventeen exploited Samsung CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 6% of this vendor portfolio.
- 94%
- Covered by CISA
- 6%
- Beyond CISA
- 4
- Product families
Attested Samsung CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-34068
Samsung WLAN AP WEA453e < 5.2.4.T1 Unauthenticated RCE via command1 and command2 Parameters |
WLAN AP WEA453e | High | Beyond CISA | 16 Feb 2026 |
|
CVE-2024-7399
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to... |
MagicINFO 9 Server | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-21042
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code. |
Samsung Mobile Devices | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-21043
Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code. |
Samsung Mobile Devices | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-4632
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to... |
MagicINFO 9 Server | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2019-16256
Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location... |
SIMalliance Toolbox Browser | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-25370
An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel... |
Samsung Mobile Devices | Confirmed | In CISA | 08 Nov 2022 |
|
CVE-2021-25369
An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace. |
Samsung Mobile Devices | Confirmed | In CISA | 08 Nov 2022 |
|
CVE-2021-25337
Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or... |
Samsung Mobile Devices | Confirmed | In CISA | 08 Nov 2022 |
|
CVE-2023-21492
Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR. |
Samsung Mobile Devices | Confirmed | In CISA | 19 May 2023 |
|
CVE-2021-25372
An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access. |
Samsung Mobile Devices | Confirmed | In CISA | 29 Jun 2023 |
|
CVE-2021-25371
A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP. |
Samsung Mobile Devices | Confirmed | In CISA | 29 Jun 2023 |
|
CVE-2021-25395
A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is... |
Samsung Mobile Devices | Confirmed | In CISA | 29 Jun 2023 |
|
CVE-2021-25394
A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio... |
Samsung Mobile Devices | Confirmed | In CISA | 29 Jun 2023 |
|
CVE-2021-25489
Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string... |
Samsung Mobile Devices | Confirmed | In CISA | 29 Jun 2023 |
|
CVE-2021-25487
Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in... |
Samsung Mobile Devices | Confirmed | In CISA | 29 Jun 2023 |
|
CVE-2022-22265
An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code... |
Samsung Mobile Devices | Confirmed | In CISA | 18 Sep 2023 |
No Samsung CVEs match this search or filter.
Showing 17 of 17 Samsung known exploited vulnerabilities.
Recurring weakness patterns
Check or handling, out-of-bounds write, and limitation account for seven mapped occurrences across this Samsung KEV portfolio.
CWE-703
Improper Check or Handling of Exceptional Conditions
CWE-787
Out-of-bounds Write
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-269
Improper Privilege Management
CWE-306
Missing Authentication for Critical Function
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CWE-416
Use After Free
CWE-434
Unrestricted Upload of File with Dangerous Type
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.