Improper authorization in wireless download protocol in Galaxy Watch prior to SMR Apr-2025 Release 1 allows physical attackers to update device unique identifier of Watch devices.
References
| Link | Resource |
|---|---|
| https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=04 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2025-04-08 05:15
Updated : 2026-01-27 17:54
NVD link : CVE-2025-20939
Mitre link : CVE-2025-20939
CVE.ORG link : CVE-2025-20939
JSON object : View
Products Affected
samsung
- wear_os
- galaxy_watch_5_pro
- galaxy_watch_ultra
- galaxy_watch_5
- galaxy_watch_4_classic
- galaxy_watch_6_classic
- galaxy_watch
- galaxy_watch_4
- galaxy_watch_7
- galaxy_watch_fe
- galaxy_watch_6
CWE
