CVE-2025-21015: Path Traversal
Published Aug 6, 2025
·Updated
Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document scanner's privilege.
Affected Software
7 affected components
Document scanner Document scanner<SMR Aug-2025 Release 1
Samsung Android=15.0-smr-apr-2025-r1
Samsung Android=15.0-smr-feb-2025-r1
Samsung Android=15.0-smr-jul-2025-r1
Samsung Android=15.0-smr-jun-2025-r1
Samsung Android=15.0-smr-mar-2025-r1
Samsung Android=15.0-smr-may-2025-r1
Event History
Aug 6, 2025
CVE Published
via MITRE·04:23 AM
Data Sourced
via MITRE·04:23 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-21015?
CVE-2025-21015 is classified as a high severity vulnerability due to its potential to allow local attackers to delete files with Document scanner's privileges.
2
How do I fix CVE-2025-21015?
To fix CVE-2025-21015, upgrade to Document scanner SMR Aug-2025 Release 1 or later.
3
Who is affected by CVE-2025-21015?
CVE-2025-21015 affects users of the Document scanner software prior to SMR Aug-2025 Release 1.
4
What type of vulnerability is CVE-2025-21015?
CVE-2025-21015 is a path traversal vulnerability that can be exploited to delete files.
5
Can CVE-2025-21015 be exploited remotely?
No, CVE-2025-21015 requires local access to exploit the path traversal vulnerability.