Impact
The vulnerability originates from incorrect default permissions in the WLAN security firmware of Samsung Mobile Devices released prior to the SMR Jul-2026 Release 1. According to the description, local attackers can exploit these permissive controls to reconfigure TencentWifiSecurity settings. This Access Control weakness (CWE-284) enables manipulation of wireless parameters, thereby allowing an attacker to change configuration settings that govern the device’s WLAN functionality.
Affected Systems
Samsung Mobile Devices running firmware versions prior to the SMR Jul-2026 Release 1 update are affected. All devices that have not received the July 2026 security corrected permission model.
Risk and Exploitability
The CVSS score of 5.1 places this issue in the medium severity range. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The description indicates that the flaw requires local access, so the attack vector is local. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment