#VU125794 Race condition in Samsung products - CVE-2025-54601
Published: April 10, 2026
Vulnerability identifier: #VU125794
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-54601
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Exynos 980
Exynos 850
Exynos 1080
Exynos 1280
Exynos 1330
Exynos 1380
Exynos 1480
Exynos 1580
Exynos W920
Exynos W930
Exynos W1000
Exynos 980
Exynos 850
Exynos 1080
Exynos 1280
Exynos 1330
Exynos 1380
Exynos 1480
Exynos 1580
Exynos W920
Exynos W930
Exynos W1000
Software vendor:
Samsung
Samsung
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper synchronization on a global variable in the Wi-Fi driver. A local user can invoke an ioctl function, exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system.
Remediation
Install updates from vendor's website.