CVE-2026-23792: Medium severity Samsung NR RRC (baseband) vulnerability
An issue was discovered in NR RRC in Samsung Mobile Processor and Modem Exynos 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W1000, Modem 5300, Modem 5400, and Modem 5410. Incorrect handling of unauthenticated downlink RRC Setup messages can cause the baseband to crash.
Affected Software
Event History
Frequently Asked Questions
Which devices are potentially exposed?
Devices using Samsung NR RRC baseband components in Exynos 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, or W1000, or Modem 5300, 5400, or 5410, are potentially affected.
What access does an attacker need?
The issue is network-reachable and does not require privileges or user interaction. Exploitation has high attack complexity and involves unauthenticated downlink RRC Setup messages.
What is the expected security impact?
Successful exploitation can crash the baseband, resulting in an availability impact. The provided assessment indicates no confidentiality or integrity impact.