Impact
Path traversal vulnerability in GalaxyDiagnostics prior to the SMR Sep-2026 Release 1 permits an attacker with physical access to the device to read files that should only be accessible with system privileges. This flaw arises from inadequate validation of file paths, allowing traversal outside of the intended directory. If exploited, an attacker could obtain sensitive system files and potentially enable further malicious actions on Samsung mobile devices running GalaxyDiagnostics prior to the SMR Sep-2026 Release 1. No specific device models or firmware revisions are listed beyond the general product names in the CNA entry.
Affected Systems
The affected systems are Samsung mobile devices that run GalaxyDiagnostics before the SMR Sep-2026 Release 1. The CNA entry lists the product as Samsung Mobile Devices, but no specific models or firmware versions are specified beyond that. Therefore, any Samsung device with a GalaxyDiagnostics.
Risk and Exploitability
The CVSS score is 6.8, indicating moderate severity. The EPSS score is less than 1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Because the path traversal requires a physical adversary interacting directly with the device, the attack vector is most likely local physical access. No patch or workaround is listed, so the risk remains until an update is applied or the application is otherwise disabled.
OpenCVE Enrichment