An issue was discovered in the WiFi driver in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580. Mishandling of an NL80211 vendor command leads to a buffer overflow.
References
| Link | Resource |
|---|---|
| https://semiconductor.samsung.com/support/quality-support/product-security-updates/ | Vendor Advisory |
| https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-49495/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
History
09 Jan 2026, 14:14
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Samsung exynos 1480
Samsung exynos 1380 Firmware Samsung exynos 1480 Firmware Samsung Samsung exynos 1580 Firmware Samsung exynos 2400 Firmware Samsung exynos 1580 Samsung exynos 2400 Samsung exynos 1380 |
|
| References | () https://semiconductor.samsung.com/support/quality-support/product-security-updates/ - Vendor Advisory | |
| References | () https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-49495/ - Vendor Advisory | |
| CPE | cpe:2.3:h:samsung:exynos_1480:-:*:*:*:*:*:*:* cpe:2.3:o:samsung:exynos_1380_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:samsung:exynos_2400_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_2400:-:*:*:*:*:*:*:* cpe:2.3:o:samsung:exynos_1580_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_1580:-:*:*:*:*:*:*:* cpe:2.3:o:samsung:exynos_1480_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_1380:-:*:*:*:*:*:*:* |
05 Jan 2026, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.4 |
| CWE | CWE-120 |
05 Jan 2026, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-05 19:15
Updated : 2026-01-09 14:14
NVD link : CVE-2025-49495
Mitre link : CVE-2025-49495
CVE.ORG link : CVE-2025-49495
JSON object : View
Products Affected
samsung
- exynos_1480
- exynos_2400
- exynos_1380_firmware
- exynos_1580
- exynos_1480_firmware
- exynos_1580_firmware
- exynos_2400_firmware
- exynos_1380
CWE
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
