Description
An issue was discovered in Wi-Fi in Samsung Mobile Processor Exynos 850, 1280, 1330, 1380, 1480, 2400, W920, and W930. A malformed Netlink command can trigger an out-of-bounds read, potentially leading to information leakage.
Published: 2026-09-14
Score: 2.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Leakage
Action: Assess Impact
AI Analysis

Impact

A malformed Netlink command can trigger an out‑of‑bounds read in the Wi‑Fi driver of Samsung Exynos processors, potentially allowing an attacker to read sensitive memory contents. The weakness is an improper read of memory beyond an array bounds (CWE‑125), which can expose confidential data without modifying system state.

Affected Systems

This vulnerability affects Samsung’s Exynos 850, 1280, 1330, 1380, 1480, 2400 firmware, as well as the W920 details are provided, so all current releases of these devices are potentially impacted until a patch is published.

Risk and Exploitability

The CVSS score of 2.8 indicates low severity, and KEV is not listed. The EPSS score of < 1% indicates a very low exploitation probability. The likely attack vector is inferred to require an attacker who can send crafted Netlink messages to the Wi‑Fi driver, which may necessitate local or privileged access to the device. While no public exploits are known, the potential for information leakage warrants monitoring of local Wi‑Fi activity.

Generated by OpenCVE AI on September 15, 2026 at 16:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Samsung firmware update for the Exynos Wi‑Fi firmware as soon as it becomes available.
  • If the device does not require Wi‑Fi, disable the Wi‑Fi interface to eliminate the vulnerable code path.
  • Restrict local access to Netlink sockets to privileged or trusted processes only, for example by applying SELinux or AppArmor restrictions.

Generated by OpenCVE AI on September 15, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in Samsung Exynos Wifi Driver Leading to Information Leakage

Mon, 14 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Title Malformed Netlink Command Causes Out‑of‑Bounds Read in Samsung Exynos 850 Wi‑Fi

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title Malformed Netlink Command Causes Out‑of‑Bounds Read in Samsung Exynos 850 Wi‑Fi

Mon, 14 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Wi-Fi in Samsung Mobile Processor Exynos 850, 1280, 1330, 1380, 1480, 2400, W920, and W930. A malformed Netlink command can trigger an out-of-bounds read, potentially leading to information leakage.
First Time appeared Samsung
Samsung exynos 850 Firmware
Weaknesses CWE-125
CPEs cpe:2.3:a:samsung:exynos_850_firmware:*:*:*:*:*:*:*:*
Vendors & Products Samsung
Samsung exynos 850 Firmware
References
Metrics cvssV3_1

{'score': 2.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N'}


Subscriptions

Samsung Exynos 850 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T15:12:33.539Z

Reserved: 2026-03-24T00:00:00.000Z

Link: CVE-2026-33962

cve-icon Vulnrichment

Updated: 2026-09-14T15:12:29.845Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T02:17:14.703

Modified: 2026-09-22T19:56:19.073

Link: CVE-2026-33962

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:30:11Z

Weaknesses