CVE-2025-21078
8.8Samsung · Mobile Smart Switch
Samsung Mobile Smart Switch uses insufficiently random values for the secretKey, allowing adjacent attackers to access sensitive backup data from applications.
Executive summary
A cryptographic weakness in Samsung Mobile Smart Switch allows adjacent attackers to compromise sensitive backup data, necessitating an immediate update to version 3.7.68.6 or later.
Vulnerability
This vulnerability involves the use of insufficiently random values for the secretKey (CWE-330), which permits unauthenticated, adjacent attackers to bypass security protections and access application backup data.
Business impact
The ability for an unauthorized party to access backup data poses a severe risk to organizational and personal data privacy, potentially exposing sensitive credentials or proprietary application information. With a CVSS score of 8.8, this high-severity vulnerability indicates a significant threat to confidentiality, integrity, and availability, warranting prioritized remediation to prevent potential data exfiltration.
Remediation
Immediate Action: Update Samsung Mobile Smart Switch to version 3.7.68.6 or later to ensure proper cryptographic entropy for the secretKey.
Proactive Monitoring: Review network access logs for suspicious activity originating from the local network segment, specifically focusing on unauthorized attempts to interface with the Smart Switch application.
Compensating Controls: Restrict access to the local network where mobile devices are connected and ensure that sensitive data backups are encrypted with additional layers of protection where possible.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Given the high CVSS score and the direct impact on backup data confidentiality, organizations should treat this vulnerability with urgency. Administrators must verify the version of the Mobile Smart Switch in use across all managed devices and enforce the update to version 3.7.68.6 to eliminate the cryptographic weakness.