CVE-2025-27891
Published: 14 May 2025
Summary
CVE-2025-27891 is a critical-severity Out-of-bounds Read (CWE-125) vulnerability in Samsung Exynos 980 Firmware. Its CVSS base score is 9.1 (Critical).
Operationally, ranked in the top 37.2% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-14886
Vulnerability details
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The lack of a length check leads…
more
to out-of-bounds reads via malformed NAS packets.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.