← Vulnerability feed

Vulnerability record · CVE-2025-54329 · published 4 November 2025

CVE-2025-54329: Samsung exynos 1280 firmware heap-based buffer overflow vulnerability

Samsung · Exynos 1280 Firmware

An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. The function used to send a multiple-payloads message (including an SMS message) lacks bounds checking, which can lead to a heap overflow.

7.5 CVSS 3.1 High EPSS 0.39% · top 69.9% CWE-122 · Heap-based buffer overflow
7.5CVSS 3.1 base score
0.39%EPSS exploitation probability, 30 days
NoNot in CISA KEV
18Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. The function used to send a multiple-payloads message (including an SMS message) lacks bounds checking, which can lead to a heap overflow.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

18 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-54329 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-54328Samsung exynos 980 firmware stack-based buffer overflow vulnerabilityAn issue was discovered in SMS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1…EPSS 0.52%9.8CVE-2025-52908Samsung exynos w1000 firmware classic buffer overflow vulnerabilityAn issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W…EPSS 0.50%9.8CVE-2025-62818Samsung exynos 990 firmware out-of-bounds write vulnerabilityAn issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 24…EPSS 0.46%9.8CVE-2025-52909Samsung exynos w1000 firmware classic buffer overflow vulnerabilityAn issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W…EPSS 0.50%9.8CVE-2025-52910Samsung exynos 1280 firmware use after free vulnerabilityAn issue was discovered in the GPU in Samsung Mobile Processor and Wearable Processor Exynos 1280, 2200, 1330, 1380, 1480, 2400. A Use-After-Free lea…EPSS 0.37%9.8CVE-2023-28613Samsung exynos 1280 firmware integer overflow vulnerabilityAn issue was discovered in Samsung Exynos Mobile Processor and Baseband Modem Processor for Exynos 1280, Exynos 2200, and Exynos Modem 5300. An integ…EPSS 1.2%9.8CVE-2023-26076Samsung exynos 1280 firmware classic buffer overflow vulnerabilityAn issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and …EPSS 0.93%9.8CVE-2023-26073Samsung exynos 850 firmware out-of-bounds write vulnerabilityAn issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exyno…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2025-54329), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.