← All Advisories

Samsung Exynos Modem SMS Processing Stack-Based Buffer Overflow, Scoring CVSS 10.0 and Affecting Processors from Exynos 980 Through Exynos 2500 and Multiple Modem Generations

Last refreshed2026-09-28

Status: UPDATED  |  Advisory ID: CVE-2025-54328

Key Details

CVECVE-2025-54328
CVSS Score / Version10.0 (Critical) / CVSS v3.1
Updated2026-07-24
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productssee table below
Classified asCWE-121 (Stack-based Buffer Overflow)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Samsungexynos_990_firmware
Samsungexynos_980_firmware
Samsungexynos_850_firmware
Samsungexynos_1080_firmware
Samsungexynos_1280_firmware
Samsungexynos_1330_firmware
Samsungexynos_1380_firmware
Samsungexynos_1480_firmware
Samsungexynos_1580_firmware
Samsungexynos_2100_firmware
Samsungexynos_2200_firmware
Samsungexynos_2400_firmware
Samsungexynos_2500_firmware
Samsungexynos_w930_firmware
Samsungexynos_w920_firmware
Samsungexynos_w1000_firmware
Samsungexynos_modem_5400_firmware
Samsungexynos_modem_5300_firmware
Samsungexynos_modem_5123_firmware
Samsungexynos_9110_firmware
SubsystemsGeneral OT
SectorsMultiple

What to Know

An issue was discovered in SMS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. A Stack-based Buffer Overflow occurs while parsing SMS RP-DATA messages. (NVD)

What to Do

Monitor Samsung's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-54328
CVEhttps://www.cve.org/CVERecord?id=CVE-2025-54328
Vendor advisoryhttps://semiconductor.samsung.com/support/quality-support/product-security-updates/