← Vulnerability feed

Vulnerability record · CVE-2025-49495 · published 5 January 2026

CVE-2025-49495: Samsung exynos 1380 firmware classic buffer overflow vulnerability

Samsung · Exynos 1380 Firmware

An issue was discovered in the WiFi driver in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580. Mishandling of an NL80211 vendor command leads to a buffer overflow.

8.4 CVSS 3.1 High EPSS 0.16% · top 95.9% CWE-120 · Classic buffer overflow
8.4CVSS 3.1 base score
0.16%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in the WiFi driver in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580. Mishandling of an NL80211 vendor command leads to a buffer overflow.

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-49495 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-54328Samsung exynos 980 firmware stack-based buffer overflow vulnerabilityAn issue was discovered in SMS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1…EPSS 0.52%9.8CVE-2025-52908Samsung exynos w1000 firmware classic buffer overflow vulnerabilityAn issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W…EPSS 0.50%9.8CVE-2025-62818Samsung exynos 990 firmware out-of-bounds write vulnerabilityAn issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 24…EPSS 0.46%9.8CVE-2025-52909Samsung exynos w1000 firmware classic buffer overflow vulnerabilityAn issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W…EPSS 0.50%9.8CVE-2025-52910Samsung exynos 1280 firmware use after free vulnerabilityAn issue was discovered in the GPU in Samsung Mobile Processor and Wearable Processor Exynos 1280, 2200, 1330, 1380, 1480, 2400. A Use-After-Free lea…EPSS 0.37%9.1CVE-2025-58349Samsung exynos 990 firmware uncontrolled resource consumption vulnerabilityAn issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 14…EPSS 0.31%9.1CVE-2025-27807Samsung exynos 990 firmware out-of-bounds write vulnerabilityAn issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 24…EPSS 0.36%9.1CVE-2025-47202Samsung exynos 980 firmware out-of-bounds write vulnerabilityIn RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 9110, W…EPSS 0.39%

Source: NIST National Vulnerability Database (record CVE-2025-49495), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.