{"id":"CVE-2025-21062","title":"Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to replace the restoring application","summary":"Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to replace the restoring application. User interaction is required for triggering this vulnerability.","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-327"],"vendor":"samsung","product":"smart_switch","affected":["smart_switch < 3.7.67.2"],"patched":["smart_switch 3.7.67.2"],"published":"2025-10-10","updated":"2026-10-08","sourceUpdated":"2026-10-08T13:10:00.200","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-21062","references":[{"url":"https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=10","label":"mobile.security@samsung.com"}],"tags":["nvd"],"epss":0.00103,"epssPercentile":0.00915,"ingestedAt":"2026-10-08T13:42:55.073Z","slug":"CVE-2025-21062","body":"## Overview\n\nUse of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to replace the restoring application. User interaction is required for triggering this vulnerability.\n\n## Affected\n\n- `smart_switch < 3.7.67.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `smart_switch 3.7.67.2`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}