Impact
wpa_supplicant includes an input validation flaw that permits adjacent attackers to write beyond the bounds of allocated memory. This buffer overflow can corrupt internal data structures, potentially enabling arbitrary code execution or causing the device to crash. The improper validation directly maps to a classic buffer-based write weakness, underscoring the risk of privilege escalation or denial of service.
Affected Systems
All Samsung Mobile Devices running wpa_supplicant versions prior to the SMR Sep‑2026 Release 1 update are vulnerable. The vulnerability applies to the base Wi‑Fi supplicant component that handles authentication and connectivity on these devices.
Risk and Exploitability
With a CVSS score of 6.1 the vulnerability is considered moderate. The EPSS score is unavailable, and it is not listed in CISA’s KEV catalog, indicating no publicly known exploits yet. The lack of a remote network attack vector suggests the attacker must be adjacent or have local access to the device. While the risk is moderate, the severity warrants timely mitigation once a patch becomes available.
OpenCVE Enrichment