Vulnerability record · CVE-2021-25489 · published 6 October 2021
CVE-2021-25489: Samsung Android modem driver format string bug causes kernel panic
Samsung · Android
Samsung Android devices contain a missing input validation flaw in the modem interface driver, resulting in a format string bug. It is listed in CISA KEV, so it has been exploited in the wild despite a medium CVSS score.
Description
Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityIt is in CISA KEV with confirmed exploitation, but impact is limited to local denial of service requiring prior radio permission.
What it is
Samsung Android devices contain a missing input validation flaw in the modem interface driver, resulting in a format string bug. It is listed in CISA KEV, so it has been exploited in the wild despite a medium CVSS score.
Impact
An attacker who already holds radio permission can trigger a kernel panic, causing a denial of service on the device. There is no confidentiality or integrity impact per the CVSS vector.
Attack surface
The vector is local (AV:L) with low privileges required (PR:L) and no user interaction (UI:N), so the attacker must already have radio permission on the device. It is not remotely reachable without that local access.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2023-06-29, confirming real-world exploitation. EPSS is low at 0.00531 (43.5th percentile), and no ransomware use is documented.
What to do
- Apply the Samsung SMR Oct-2021 Release 1 or later update to affected devices.
- If updates are unavailable, discontinue use of the affected product per CISA guidance.
- Restrict or monitor apps and processes granted radio permission.
- Track device patch levels and enforce minimum security patch versions.
Detection
- Monitor for kernel panic events and unexpected device reboots on Samsung Android devices.
- Audit which apps hold radio permission and alert on unusual grants.
- Correlate device crash logs with modem interface driver activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-25489 to the Known Exploited Vulnerabilities catalog on 29 June 2023 as "Samsung Mobile Devices Improper Input Validation Vulnerability". Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable Federal deadline 20 July 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=10 | Vendor Advisory |
| https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=10 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-25489 | US Government Resource |
Track CVE-2021-25489 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-25489), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.