An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. The lack of a length check leads to out-of-bounds reads via malformed NAS packets.
CVE ID: CVE-2025-27891
CVSS Base Severity: CRITICAL
CVSS Base Score: 9.1
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Vendor: n/a
Product: n/a
EPSS Score: 0.06% (probability of being exploited)
EPSS Percentile: 17.58% (scored less or equal to compared to others)
EPSS Date: 2025-06-06 (when was this score calculated)