External risk intelligence

Samsung Exynos LTE Baseband Crash Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2025-58349

The vulnerability involves LTE baseband processing in mobile and wearable processors. While it is theoretically reachable via radio signals from a nearby malicious transmitter, this does not constitute public internet exposure in the common sense of remote network access, nor is it limited to internal/local-only scenarios. It represents a physical proximity-based exposure vector.

Samsung Exynos 990 Firmware

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in Samsung's mobile and wearable processors that impacts the handling of LTE network packets. This issue can lead to a crash of the baseband processor, which is a critical component for device communication. The broad range of affected products means this warrants attention to confirm relevance to your device ecosystem.

  • Crashes baseband communication on Samsung devices.
  • A potential disruption to mobile and wearable device connectivity.
  • Assess impact and confirm device relevance.

Attack Path

How an attacker could exploit the issue

An attacker could send specially crafted LTE MAC packets to a vulnerable Samsung processor. The processor's baseband component, responsible for handling these packets, fails to process a large number of Control Elements correctly. This incorrect handling causes the baseband to crash.

  • Network access required.
  • Malformed LTE MAC packets trigger the issue.
  • Baseband crash, leading to denial of service.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could affect the stability of devices utilizing Samsung Exynos processors, including mobile phones and wearables. An attacker could potentially cause these devices to crash when they process specially crafted LTE MAC packets.

  • Device baseband could crash.
  • Crafted LTE packets could trigger crash.
  • Device instability and service disruption.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts Samsung's Exynos processors, modems, and wearable processors, potentially leading to baseband crashes. Identifying affected devices within your environment, assessing their exposure, and confirming ownership are the critical first steps. This will enable prioritized remediation planning to mitigate risks effectively.

  • Ownership rests with device or platform teams.
  • Verify device reachability and criticality first.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Samsung Exynos processor and modem lineup mentioned in CVE-2025-58349?

These are specialized chipsets produced by Samsung that handle essential communication tasks, including mobile connectivity, in many smartphones and wearable devices. They include various Exynos mobile and wearable processor models—such as the 990, 2400, and W1000—as well as dedicated 5123, 5300, and 5400 modems. These components act as the bridge between the device hardware and wireless cellular networks, managing signal transmission and data processing.

What is the weakness class behind CVE-2025-58349?

This vulnerability is classified as CWE-400, which refers to Uncontrolled Resource Consumption. In plain language, this means the software does not properly limit or manage the amount of data it processes when receiving specific inputs. In this case, the baseband fails to handle a high volume of LTE MAC Control Elements, causing it to become overwhelmed and crash.

How can an attacker trigger this CVE-2025-58349 crash?

An attacker needs to transmit specially crafted LTE MAC packets that contain a high number of Control Elements (CEs) to a vulnerable device. If the device's baseband processor receives and attempts to handle these malformed packets, it encounters an error that leads to a crash. Ordinary, legitimate LTE network traffic that does not contain these specific, complex groupings of Control Elements will not trigger the bug.

Do I need to worry if my device is internet-facing?

Halo Surface Signal notes that while this is an external-facing issue, it is not traditional internet exposure. Because the vulnerability exists at the LTE baseband level, it relies on physical proximity to a transmitter rather than remote access over the public internet. The risk is relevant for any environment where devices rely on these specific Exynos modems for cellular communication, regardless of whether they are typically categorized as internal or external-facing assets.

Is there a practical first step for handling CVE-2025-58349?

The most effective first step is to inventory your device fleet to identify which units contain the specific Samsung Exynos processors or modems listed in this advisory. Once you have a clear picture of the potentially affected devices in your environment, focus on coordinating with your device or platform teams to track official vendor firmware updates. Prioritize this based on the business criticality of the devices and their actual presence in your operational network.

References