CVE-2025-54602

EUVD-2025-209245
An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000. Improper synchronization on a global variable leads to a use-after-free. An attacker can trigger a race condition by invoking an ioctl function concurrently from multiple threads.
Race Condition
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7 HIGH
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 2%
Affected Products (NVD)
VendorProductVersion
samsungexynos_980_firmware
-
samsungexynos_850_firmware
-
samsungexynos_1080_firmware
-
samsungexynos_1280_firmware
-
samsungexynos_1330_firmware
-
samsungexynos_1380_firmware
-
samsungexynos_1480_firmware
-
samsungexynos_1580_firmware
-
samsungexynos_w1000_firmware
-
samsungexynos_w920_firmware
-
samsungexynos_w930_firmware
-
𝑥
= Vulnerable software versions