An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000. Incorrect Handling of the NL80211 vendor command leads to a buffer overflow via a certain ioctl message, issue 1 of 2.
References
| Link | Resource |
|---|---|
| https://semiconductor.samsung.com/support/quality-support/product-security-updates/ | Vendor Advisory |
| https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-52908/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
Configuration 7 (hide)
| AND |
|
Configuration 8 (hide)
| AND |
|
Configuration 9 (hide)
| AND |
|
Configuration 10 (hide)
| AND |
|
History
09 Apr 2026, 18:54
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Samsung exynos W1000
Samsung exynos 1380 Firmware Samsung exynos W1000 Firmware Samsung exynos 1580 Firmware Samsung exynos 1330 Samsung exynos 980 Firmware Samsung exynos 1280 Firmware Samsung exynos W930 Samsung exynos 1480 Samsung exynos W920 Samsung exynos 1480 Firmware Samsung exynos W930 Firmware Samsung Samsung exynos 1280 Samsung exynos 1330 Firmware Samsung exynos 1580 Samsung exynos W920 Firmware Samsung exynos 980 Samsung exynos 850 Samsung exynos 1380 Samsung exynos 850 Firmware |
|
| References | () https://semiconductor.samsung.com/support/quality-support/product-security-updates/ - Vendor Advisory | |
| References | () https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-52908/ - Vendor Advisory | |
| CPE | cpe:2.3:o:samsung:exynos_w1000_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:samsung:exynos_1280_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:samsung:exynos_1380_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_850:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_w920:-:*:*:*:*:*:*:* cpe:2.3:o:samsung:exynos_980_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_w930:-:*:*:*:*:*:*:* cpe:2.3:o:samsung:exynos_w930_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_1330:-:*:*:*:*:*:*:* cpe:2.3:o:samsung:exynos_1330_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_1480:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_1280:-:*:*:*:*:*:*:* cpe:2.3:o:samsung:exynos_1580_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_1580:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_980:-:*:*:*:*:*:*:* cpe:2.3:o:samsung:exynos_1480_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_1380:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_w1000:-:*:*:*:*:*:*:* cpe:2.3:o:samsung:exynos_w920_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:samsung:exynos_850_firmware:-:*:*:*:*:*:*:* |
09 Apr 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-120 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
07 Apr 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-07 16:16
Updated : 2026-04-09 18:54
NVD link : CVE-2025-52908
Mitre link : CVE-2025-52908
CVE.ORG link : CVE-2025-52908
JSON object : View
Products Affected
samsung
- exynos_1480
- exynos_1330
- exynos_1580
- exynos_1580_firmware
- exynos_850_firmware
- exynos_w930
- exynos_w920
- exynos_1380_firmware
- exynos_w920_firmware
- exynos_w1000
- exynos_850
- exynos_1280
- exynos_1280_firmware
- exynos_980
- exynos_w1000_firmware
- exynos_w930_firmware
- exynos_1380
- exynos_1330_firmware
- exynos_1480_firmware
- exynos_980_firmware
CWE
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
