VendorsSamsungsmart_switchany version
Vulnerabilities

Samsung Smart Switch any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2026-20998
Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication.
Published 2026-03-16 · Analyzed
9.8EPSS 0.005
CVE-2026-20997
Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to potentially bypass authentication.
Published 2026-03-16 · Analyzed
9.8EPSS 0.003
CVE-2025-21064
Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data.
Published 2025-10-10 · Analyzed
8.8EPSS 0.003
CVE-2025-21078
Use of insufficiently random value of secretKey in Smart Switch prior to version 3.7.68.6 allows adjacent attackers to access backup data from applications.
Published 2025-11-05 · Analyzed
8.8EPSS 0.002
CVE-2025-21062
Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to replace the restoring application. User interaction is required for triggering this vulnerability.
Published 2025-10-10 · Analyzed
7.8EPSS 0.001
CVE-2026-20999
Authentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger privileged functions.
Published 2026-03-16 · Analyzed
7.5EPSS 0.003
CVE-2026-21005
Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Smart Switch privilege.
Published 2026-03-16 · Analyzed
7.1EPSS 0.002
CVE-2026-20996
Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attackers to configure a downgraded scheme for authentication.
Published 2026-03-16 · Analyzed
7.1EPSS 0.002
CVE-2025-21061
Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access sensitive data. User interaction is required for triggering this vulnerability.
Published 2025-10-10 · Analyzed
7.1EPSS 0.001
CVE-2026-21079
Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data.
Published 2026-08-10 · Analyzed
7.0EPSS 0.001
CVE-2026-21004
Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service.
Published 2026-03-16 · Analyzed
6.9EPSS 0.002
CVE-2026-21080
Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.
Published 2026-08-10 · Analyzed
6.9EPSS 0.002
CVE-2026-21083
Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.
Published 2026-08-10 · Analyzed
6.8EPSS 0.003
CVE-2026-21078
Insufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows adjacent attackers to spoof device identity.
Published 2026-08-10 · Analyzed
6.5EPSS 0.002
CVE-2025-21060
Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access backup data from applications. User interaction is required for triggering this vulnerability.
Published 2025-10-10 · Analyzed
5.5EPSS 0.001
CVE-2026-20995
Exposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69.15 allows remote attackers to set a specific configuration.
Published 2026-03-16 · Analyzed
5.3EPSS 0.003
CVE-2025-20996
Improper authorization in Smart Switch installed on non-Samsung Device prior to version 3.7.64.10 allows local attackers to read data with the privilege of Smart Switch. User interaction is required for triggering this vulnerability.
Published 2025-06-04 · Analyzed
5.0EPSS 0.001