Sun vendor intelligence
Sun Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Sun products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 19
- Known exploited vulnerabilities affecting Sun products
- In CISA KEV
- 18
- Records also listed in the official catalog
- Beyond CISA KEV
- 1
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- Sun KEVs with sensor-observed exploitation activity
The catalog gap matters for Sun exposure
One of the nineteen exploited Sun CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 5% of this vendor portfolio.
- 95%
- Covered by CISA
- 5%
- Beyond CISA
- 6
- Product families
Attested Sun CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-34068
Samsung WLAN AP WEA453e < 5.2.4.T1 Unauthenticated RCE via command1 and command2 Parameters |
WLAN AP WEA453e | High | Beyond CISA | 16 Feb 2026 |
|
CVE-2024-7399
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to... |
MagicINFO 9 Server | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-21042
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code. |
Samsung Mobile Devices | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-21043
Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code. |
Samsung Mobile Devices | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-4632
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to... |
MagicINFO 9 Server | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2019-16256
Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location... |
SIMalliance Toolbox Browser | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2008-3431
The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communication method for IOCTLs and... |
xVM VirtualBox | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2021-25370
An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel... |
Samsung Mobile Devices | Confirmed | In CISA | 08 Nov 2022 |
|
CVE-2021-25369
An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace. |
Samsung Mobile Devices | Confirmed | In CISA | 08 Nov 2022 |
|
CVE-2021-25337
Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or... |
Samsung Mobile Devices | Confirmed | In CISA | 08 Nov 2022 |
|
CVE-2023-21492
Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR. |
Samsung Mobile Devices | Confirmed | In CISA | 19 May 2023 |
|
CVE-2021-25372
An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access. |
Samsung Mobile Devices | Confirmed | In CISA | 29 Jun 2023 |
|
CVE-2021-25371
A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP. |
Samsung Mobile Devices | Confirmed | In CISA | 29 Jun 2023 |
|
CVE-2021-25395
A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is... |
Samsung Mobile Devices | Confirmed | In CISA | 29 Jun 2023 |
|
CVE-2021-25394
A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio... |
Samsung Mobile Devices | Confirmed | In CISA | 29 Jun 2023 |
|
CVE-2021-25489
Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string... |
Samsung Mobile Devices | Confirmed | In CISA | 29 Jun 2023 |
|
CVE-2021-25487
Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in... |
Samsung Mobile Devices | Confirmed | In CISA | 29 Jun 2023 |
|
CVE-2022-22265
An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code... |
Samsung Mobile Devices | Confirmed | In CISA | 18 Sep 2023 |
|
CVE-2021-36380
Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi. |
SureLine | Confirmed | In CISA | 05 Mar 2024 |
No Sun CVEs match this search or filter.
Showing 19 of 19 Sun known exploited vulnerabilities.
Recurring weakness patterns
Check or handling, limitation, and out-of-bounds write account for seven mapped occurrences across this Sun KEV portfolio.
CWE-703
Improper Check or Handling of Exceptional Conditions
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-787
Out-of-bounds Write
CWE-269
Improper Privilege Management
CWE-306
Missing Authentication for Critical Function
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CWE-416
Use After Free
CWE-434
Unrestricted Upload of File with Dangerous Type
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.