CVE-2025-20997: Medium severity Samsung Galaxy Watch vulnerability
Published Jul 8, 2025
·Updated
Incorrect default permission in Framework for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to reset some configuration of Galaxy Watch.
Affected Software
12 affected components
Samsung Galaxy Watch<SMR Jul-2025 Release 1
All of the following
Samsung Wear Os=5.0
Any of the following
Samsung Galaxy Watch
Samsung Galaxy Watch 4
Samsung Galaxy Watch 4 Classic
Samsung Galaxy Watch 5
Samsung Galaxy Watch 5 Pro
Samsung Galaxy Watch 6
Samsung Galaxy Watch 6 Classic
Samsung Galaxy Watch 7
Samsung Galaxy Watch Fe
Samsung Galaxy Watch Ultra
Event History
Jul 8, 2025
CVE Published
via MITRE·10:34 AM
Data Sourced
via MITRE·10:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-20997?
CVE-2025-20997 is considered to have a moderate severity due to the potential for unauthorized configuration resets.
2
How do I fix CVE-2025-20997?
To address CVE-2025-20997, update the Samsung Galaxy Watch to the SMR Jul-2025 Release 1 or later.
3
What versions of Samsung Galaxy Watch are affected by CVE-2025-20997?
CVE-2025-20997 affects all versions of Samsung Galaxy Watch prior to SMR Jul-2025 Release 1.
4
What type of attacks does CVE-2025-20997 allow?
CVE-2025-20997 allows local attackers to reset certain configuration settings on the Galaxy Watch.
5
Is there a known exploit for CVE-2025-20997?
As of now, there are no known public exploits for CVE-2025-20997.