CVE-2025-20895: Medium severity samsung galaxy store vulnerability
Published Feb 4, 2025
·Updated
Authentication Bypass Using an Alternate Path in Galaxy Store prior to version 4.5.87.6 allows physical attackers to install arbitrary applications to bypass restrictions of Setupwizard.
Affected Software
2 affected components
Samsung Galaxy Store<4.5.87.6
Samsung Galaxy Store<4.5.87.6
Event History
Feb 4, 2025
CVE Published
via MITRE·07:19 AM
Data Sourced
via MITRE·07:19 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-20895?
CVE-2025-20895 is considered a high-severity vulnerability due to its potential for unauthorized access and installation of arbitrary applications.
2
How do I fix CVE-2025-20895?
To fix CVE-2025-20895, update the Galaxy Store to version 4.5.87.6 or later.
3
Who is affected by CVE-2025-20895?
CVE-2025-20895 affects users of Galaxy Store versions prior to 4.5.87.6.
4
What are the risks associated with CVE-2025-20895?
The risks associated with CVE-2025-20895 include potential unauthorized installation of malicious applications by physical attackers.
5
Can CVE-2025-20895 be exploited remotely?
CVE-2025-20895 requires physical access to the device for exploitation, limiting its remote attack vector.