{"id":"CVE-2025-62817","title":"An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500","summary":"An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference of session->ncp_hdr_buf in __pilot_parsing_ncp() causes a denial of service.","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-476"],"vendor":"samsung","product":"exynos_1280_firmware","affected":["exynos_1280_firmware","exynos_1380_firmware","exynos_1480_firmware","exynos_1580_firmware","exynos_2200_firmware","exynos_2400_firmware","exynos_2500_firmware"],"published":"2026-03-03","updated":"2026-09-21","sourceUpdated":"2026-09-21T19:17:03.440","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-62817","references":[{"url":"https://semiconductor.samsung.com/support/quality-support/product-security-updates/","label":"cve@mitre.org"},{"url":"https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-62817/","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-03-10T17:11:00.612491Z"},"epss":0.00286,"epssPercentile":0.21282,"ingestedAt":"2026-09-21T19:51:58.843Z","slug":"CVE-2025-62817","body":"## Overview\n\nAn issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference of session->ncp_hdr_buf in __pilot_parsing_ncp() causes a denial of service.\n\n## Affected\n\n- `exynos_1280_firmware`\n- `exynos_1380_firmware`\n- `exynos_1480_firmware`\n- `exynos_1580_firmware`\n- `exynos_2200_firmware`\n- `exynos_2400_firmware`\n- `exynos_2500_firmware`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}