CVE-2025-21064
8.8Samsung · Mobile Smart Switch
Improper authentication in Samsung Mobile Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access data during transfer.
Executive summary
A critical authentication flaw in Samsung Mobile Smart Switch allows adjacent attackers to intercept or access sensitive data, necessitating an immediate software update.
Vulnerability
This vulnerability involves improper authentication (CWE-287) within the Smart Switch application, which enables an unauthenticated attacker positioned on the same network segment to access data being transferred between devices.
Business impact
The vulnerability carries a CVSS score of 8.8, reflecting its high severity due to the potential for unauthorized access to sensitive user data during migration or backup processes. A successful exploit could lead to the exposure of private information, resulting in significant privacy breaches and potential compliance violations for affected users or organizations. Given that Smart Switch is frequently used to transfer entire device contents, the impact of data interception is substantial.
Remediation
Immediate Action: Update the Samsung Mobile Smart Switch application to version 3.7.66.6 or later to resolve the underlying authentication weakness.
Proactive Monitoring: Monitor network traffic for unusual connection patterns or unauthorized access attempts occurring during device data transfer intervals.
Compensating Controls: Ensure that data transfers are conducted over trusted, private networks rather than public or insecure Wi-Fi environments until the software has been patched.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The vulnerability presents a serious risk to data confidentiality during the critical process of mobile device data migration. Administrators and individual users are strongly advised to verify their installed version of Samsung Mobile Smart Switch and apply the update to version 3.7.66.6 immediately to eliminate the risk of unauthorized data access.