CVE-2025-26780

An issue was discovered in L2 in Samsung Mobile Processor and Modem Exynos 2400 and Modem 5400. The lack of a length check leads to a Denial of Service via a malformed PDCP packet.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:samsung:exynos_2400_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:exynos_2400:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:samsung:modem_5400_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:modem_5400:-:*:*:*:*:*:*:*

History

27 Oct 2025, 16:59

Type Values Removed Values Added
References () https://semiconductor.samsung.com/support/quality-support/product-security-updates/ - () https://semiconductor.samsung.com/support/quality-support/product-security-updates/ - Vendor Advisory
References () https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-26780/ - () https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-26780/ - Vendor Advisory
First Time Samsung exynos 2400
Samsung exynos 2400 Firmware
Samsung
Samsung modem 5400 Firmware
Samsung modem 5400
CPE cpe:2.3:o:samsung:modem_5400_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:samsung:exynos_2400_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:exynos_2400:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:modem_5400:-:*:*:*:*:*:*:*

08 Jul 2025, 18:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-20

08 Jul 2025, 16:18

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en L2 en Samsung Mobile Processor y Modem Exynos 2400 y módem 5400. La falta de una verificación de longitud conduce a una denegación de servicio a través de un paquete PDCP mal formado.

07 Jul 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-07 16:15

Updated : 2025-10-27 16:59


NVD link : CVE-2025-26780

Mitre link : CVE-2025-26780

CVE.ORG link : CVE-2025-26780


JSON object : View

Products Affected

samsung

  • modem_5400
  • modem_5400_firmware
  • exynos_2400_firmware
  • exynos_2400
CWE
CWE-20

Improper Input Validation