---
id: CVE-2026-33970
title: >-
  An issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearable
  Processor, and Modem Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480,
  2400, 1580, 2500, 1680, W920, W930, W1000, and Modem 5410
summary: >-
  An issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearable
  Processor, and Modem Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480,
  2400, 1580, 2500, 1680, W920, W930, W1000, and Modem 5410. In the 5G baseband,
  a NU…
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L'
cwe:
  - CWE-476
vendor: Samsung
product: Exynos 850 firmware
affected:
  - exynos_850_firmware <= 2025-12-24
published: '2026-09-14'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T19:56:19.073'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-33970'
references:
  - url: >-
      https://semiconductor.samsung.com/support/quality-support/product-security-updates/
    label: cve@mitre.org
  - url: >-
      https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2026-33970/
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
epss: 0.00315
epssPercentile: 0.21756
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-16T14:29:07.682710Z'
ingestedAt: '2026-09-14T15:23:07.467Z'
---

## Overview

An issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 1680, W920, W930, W1000, and Modem 5410. In the 5G baseband, a NULL Pointer Dereference occurs when processing a malformed RRC Reconfiguration message.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
