Protection Mechanism Failure in Bootloader for Samsung Devices
CVE-2025-20892

5.9MEDIUM

Key Information:

Vendor
Samsung
Vendor
CVE Published:
4 February 2025

Summary

A vulnerability exists in the bootloader of Samsung devices released before the January 2025 Security Maintenance Release, allowing physical attackers to execute the fastboot command. This exploitation requires user interaction to trigger, posing a risk if an unauthorized individual gains access to the device.

Affected Version(s)

Samsung Mobile Devices SMR Jan-2025 Release in Select Android 13, 14 devices using MediaTek chipset

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.