CVE-2021-25397
An improper access control vulnerability in TelephonyUI prior to SMR MAY-2021 Release 1 allows local attackers to write arbitrary files of telephony process via untrusted applications.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.8
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
- EPSS probability
- 0.02%
- CWE
- CWE-926
- Published
- 2021-06-11
- Last modified
- 2026-03-13
Affected products
- Samsung Mobile Samsung Mobile Devices
- Samsung Mobile Samsung Mobile Devices
Weakness type
Related vulnerabilities
- CVE-2025-5344 — Exposed AIDL service allowing for tampering of system secure settings in Bluebird kiosk application
- CVE-2024-13917 — Intent Injection in Kruger&Matz AppLock application
- CVE-2023-41960 — The vulnerability allows an unprivileged(untrusted) third-party application to interact with a content-provider unsafely
- CVE-2021-25388 — Improper caller check vulnerability in Knox Core prior to SMR MAY-2021 Release 1 allows attackers to install arbitrary a
- CVE-2026-81301 — Ekia File Manager 1.2.7 - Exported ContentProvider allows unauthorized file access
- CVE-2026-18994 — A potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distribute
- CVE-2024-13916 — Exposure of Applications' Encryption PINs in Kruger&Matz AppLock
- CVE-2024-13915 — Unrestricted Access to Exported Service in com.pri.factorytest