Description
Incorrect default permissions in WLAN security prior to SMR Jul-2026 Release 1 allows local attackers to configure TencentWifiSecurity settings.
Published: 2026-07-10
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability originates from incorrect default permissions in the WLAN security firmware of Samsung Mobile Devices released prior to the SMR Jul-2026 Release 1. According to the description, local attackers can exploit these permissive controls to reconfigure TencentWifiSecurity settings. This Access Control weakness (CWE-284) enables manipulation of wireless parameters, thereby allowing an attacker to change configuration settings that govern the device’s WLAN functionality.

Affected Systems

Samsung Mobile Devices running firmware versions prior to the SMR Jul-2026 Release 1 update are affected. All devices that have not received the July 2026 security corrected permission model.

Risk and Exploitability

The CVSS score of 5.1 places this issue in the medium severity range. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The description indicates that the flaw requires local access, so the attack vector is local. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on July 29, 2026 at 11:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device firmware to SMR Jul-2026 Release 1 or later, which restores proper default permissions for WLAN settings.
  • If an update cannot be applied immediately, restrict or disable modification of the TencentWifiSecurity settings from the device’s local management interface and enforce least‑privilege access control rules.
  • Monitor network activity for anomalous WLAN configuration changes and audit device logs for unauthorized access attempts.

Generated by OpenCVE AI on July 29, 2026 at 11:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Incorrect Default Permissions Allow Local WLAN Configuration Changes
Weaknesses CWE-284

Fri, 24 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Incorrect Default Permissions Allow Local WLAN Configuration Changes
Weaknesses CWE-284

Tue, 21 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Incorrect Default WLAN Permissions Enabling Local Configuration of TencentWifiSecurity
Weaknesses CWE-284

Wed, 15 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Incorrect Default WLAN Permissions Enabling Local Configuration of TencentWifiSecurity
Weaknesses CWE-284

Mon, 13 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Unauthorized WLAN Configuration via Incorrect Default Permissions
Weaknesses CWE-284

Sun, 12 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Unauthorized WLAN Configuration via Incorrect Default Permissions
Weaknesses CWE-284

Sat, 11 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Local Permission Abuse in Samsung Mobile WLAN Settings
Weaknesses CWE-284

Fri, 10 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Local Permission Abuse in Samsung Mobile WLAN Settings
Weaknesses CWE-284

Fri, 10 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Mobile Devices
Vendors & Products Samsung Mobile
Samsung Mobile samsung Mobile Devices

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Description Incorrect default permissions in WLAN security prior to SMR Jul-2026 Release 1 allows local attackers to configure TencentWifiSecurity settings.
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Samsung Mobile Devices
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-07-10T11:45:14.827Z

Reserved: 2025-12-11T01:33:35.819Z

Link: CVE-2026-21051

cve-icon Vulnrichment

Updated: 2026-07-10T11:45:07.633Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T11:30:17Z

Weaknesses

No weakness.