← Vulnerability feed

Vulnerability record · CVE-2016-4032 · published 13 April 2017

CVE-2016-4032: Samsung galaxy s6 firmware improper access control vulnerability

Samsung · Galaxy S6 Firmware

Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices do not block AT+USBDEBUG and AT+WIFIVALUE, which allows attackers to modify Android settings by leveraging AT access, aka SVE-2016-5301.

4.6 CVSS 3.0 Medium EPSS 0.43% · top 65.0% CWE-284 · Improper access control
4.6CVSS 3.0 base score, v2 2.1
0.43%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices do not block AT+USBDEBUG and AT+WIFIVALUE, which allows attackers to modify Android settings by leveraging AT access, aka SVE-2016-5301.

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/97650 Third Party AdvisoryVDB Entry
https://github.com/ud2/advisories/tree/master/android/samsung/nocve-2016-0004 ExploitTechnical DescriptionThird Party Advisory
http://www.securityfocus.com/bid/97650 Third Party AdvisoryVDB Entry
https://github.com/ud2/advisories/tree/master/android/samsung/nocve-2016-0004 ExploitTechnical DescriptionThird Party Advisory

Track CVE-2016-4032 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2015-1801Samsung galaxy s4 firmware memory buffer overflow vulnerabilityThe samsung_extdisp driver in the Samsung S4 (GT-I9500) I9500XXUEMK8 kernel 3.4 and earlier allows attackers to cause a denial of service (memory cor…EPSS 3.9%9.8CVE-2016-2566Samsung galaxy s6 firmware sql injection vulnerabilitySamsung SecEmailSync on SM-G920F build G920FXXU2COH2 (Galaxy S6) devices has SQL injection, aka SVE-2015-5081.EPSS 1.5%8.8CVE-2018-14745Samsung galaxy s6 firmware memory buffer overflow vulnerabilityBuffer overflow in prot_get_ring_space in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allows an attacker (who has obt…EPSS 1.9%7.5CVE-2015-1800Samsung galaxy s4 firmware information exposure vulnerabilityThe samsung_extdisp driver in the Samsung S4 (GT-I9500) I9500XXUEMK8 kernel 3.4 and earlier allows attackers to potentially obtain sensitive informat…EPSS 2.8%6.8CVE-2016-4030Samsung galaxy s6 firmware improper access control vulnerabilitySamsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I919…EPSS 0.51%6.8CVE-2016-4031Samsung galaxy s6 firmware improper access control vulnerabilitySamsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I919…EPSS 0.52%6.3CVE-2018-14852Samsung galaxy s6 firmware memory buffer overflow vulnerabilityOut-of-bounds array access in dhd_rx_frame in drivers/net/wireless/bcmdhd4358/dhd_linux.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-…EPSS 0.96%6.3CVE-2018-14854Samsung galaxy s6 firmware memory buffer overflow vulnerabilityBuffer overflow in dhd_bus_flow_ring_delete_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-Fi driver on the Samsung Gala…EPSS 0.95%

Source: NIST National Vulnerability Database (record CVE-2016-4032), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.