Description
An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 1580, 1680, W920, W930, and W1000. . A malformed ioctl command to the Wi-Fi interface device can lead to improper buffer size allocation, resulting in an out-of-bounds write and causing a denial of service (DoS).
Published: 2026-09-14
Score: 2.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Firmware
AI Analysis

Impact

A malformed ioctl command sent to the Wi‑Fi interface device causes an improper buffer allocation, leading to an out‑of‑bounds write. This flaw can crash the Wi‑Fi driver, rendering the wireless functionality unavailable and resulting in a denial of service. The vulnerability is recognized as a classic out‑of‑bounds write, classified as CWE‑787.

Affected Systems

The vulnerability affects the Samsung Exynos 1330 firmware bundle. In other families such as Exynos 1380, 1480, 1580, 1680, W920, W930, and W1000, but the published remediation specifically addresses the Exynos 1330 firmware. No firmware revision range is disclosed, so all current releases of the Exynos 1330 firmware should be considered vulnerable.

Risk and Exploitability

The CVSS score of 2.8 indicates a low severity rating, and the EPSS score of less than 1 % suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need to issue a crafted ioctl to the Wi‑Fi driver, which typically requires local or privileged access. Remote exploitation is unlikely, but a local user with sufficient privileges could trigger the crash and disrupt device operation.

Generated by OpenCVE AI on September 15, 2026 at 16:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Download and install the latest firmware update from Samsung’s semiconductor product security updates page for Exynos 1330.
  • Restrict ioctl access to the Wi‑Fi driver by limiting it to privileged users only.
  • Continuously monitor device logs for Wi‑Fi driver crashes and apply corrective measures if instability is detected.

Generated by OpenCVE AI on September 15, 2026 at 16:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Title Malformed IOCTL Buffer Overflow in Samsung Exynos Wi-Fi Driver Leading to Denial of Service

Mon, 14 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Wi‑Fi ioctl Causes DoS on Exynos 1330

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Wi‑Fi ioctl Causes DoS on Exynos 1330

Mon, 14 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 1580, 1680, W920, W930, and W1000. . A malformed ioctl command to the Wi-Fi interface device can lead to improper buffer size allocation, resulting in an out-of-bounds write and causing a denial of service (DoS).
First Time appeared Samsung
Samsung exynos 1330 Firmware
Weaknesses CWE-787
CPEs cpe:2.3:a:samsung:exynos_1330_firmware:*:*:*:*:*:*:*:*
Vendors & Products Samsung
Samsung exynos 1330 Firmware
References
Metrics cvssV3_1

{'score': 2.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L'}


Subscriptions

Samsung Exynos 1330 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T16:51:01.588Z

Reserved: 2026-03-24T00:00:00.000Z

Link: CVE-2026-33960

cve-icon Vulnrichment

Updated: 2026-09-14T16:50:54.910Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T02:17:14.547

Modified: 2026-09-22T19:56:19.073

Link: CVE-2026-33960

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:15:15Z

Weaknesses