← Vulnerability feed

Vulnerability record · CVE-2023-26498 · published 23 March 2023

CVE-2023-26498: Samsung exynos modem 5300 firmware out-of-bounds write vulnerability

Samsung · Exynos Modem 5300 Firmware

An issue was discovered in Samsung Baseband Modem Chipset for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos Auto T5126. Memory corruption can occur due to improper checking of the number of properties while parsing the chatroom attribute in the SDP (Session Description Protocol) module.

9.8 CVSS 3.1 Critical EPSS 23% · top 2.4% CWE-787 · Out-of-bounds write
9.8CVSS 3.1 base score
23%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Samsung Baseband Modem Chipset for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos Auto T5126. Memory corruption can occur due to improper checking of the number of properties while parsing the chatroom attribute in the SDP (Session Description Protocol) module.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-26498 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-54328Samsung exynos 980 firmware stack-based buffer overflow vulnerabilityAn issue was discovered in SMS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1…EPSS 0.52%9.8CVE-2025-52908Samsung exynos w1000 firmware classic buffer overflow vulnerabilityAn issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W…EPSS 0.50%9.8CVE-2025-62818Samsung exynos 990 firmware out-of-bounds write vulnerabilityAn issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 24…EPSS 0.46%9.8CVE-2025-52909Samsung exynos w1000 firmware classic buffer overflow vulnerabilityAn issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W…EPSS 0.50%9.8CVE-2023-28613Samsung exynos 1280 firmware integer overflow vulnerabilityAn issue was discovered in Samsung Exynos Mobile Processor and Baseband Modem Processor for Exynos 1280, Exynos 2200, and Exynos Modem 5300. An integ…EPSS 1.2%9.8CVE-2023-26496Samsung exynos modem 5300 firmware out-of-bounds write vulnerabilityAn issue was discovered in Samsung Baseband Modem Chipset for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T5124. M…EPSS 23%9.8CVE-2023-26497Samsung exynos modem 5300 firmware out-of-bounds write vulnerabilityAn issue was discovered in Samsung Baseband Modem Chipset for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T5125. M…EPSS 23%9.8CVE-2023-26076Samsung exynos 1280 firmware classic buffer overflow vulnerabilityAn issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and …EPSS 0.93%

Source: NIST National Vulnerability Database (record CVE-2023-26498), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.