← Vulnerability feed

Vulnerability record · CVE-2025-21062 · published 10 October 2025

CVE-2025-21062: Samsung smart switch broken cryptographic algorithm vulnerability

Samsung · Smart Switch

Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to replace the restoring application. User interaction is required for triggering this vulnerability.

7.8 CVSS 3.1 High EPSS 0.10% · top 99.1% CWE-327 · Broken cryptographic algorithm
7.8CVSS 3.1 base score
0.10%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to replace the restoring application. User interaction is required for triggering this vulnerability.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-21062 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.1CVE-2026-21005Samsung smart switch path traversal vulnerabilityPath traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Smart Switch privilege.EPSS 0.24%7.1CVE-2026-20996Samsung smart switch broken cryptographic algorithm vulnerabilityUse of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attackers to configure a downgraded scheme …EPSS 0.17%7.1CVE-2026-20998Samsung smart switch vulnerabilityImproper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication.EPSS 0.55%7.1CVE-2026-20999Samsung smart switch authentication bypass by capture-replay vulnerabilityAuthentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger privileged functions.EPSS 0.31%7.0CVE-2026-21079Samsung smart switch missing encryption vulnerabilityMissing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data.EPSS 0.10%6.9CVE-2026-21080Samsung smart switch cleartext storage of sensitive data vulnerabilityCleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.EPSS 0.17%6.9CVE-2026-21004Samsung smart switch improper authentication vulnerabilityImproper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service.EPSS 0.19%6.8CVE-2026-21083Samsung smart switch improper input validation vulnerabilityImproper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.EPSS 0.26%

Source: NIST National Vulnerability Database (record CVE-2025-21062), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.