CVE-2025-20886
CVSS 3.1 Score 4.4 of 10 (medium)
Details
Published Feb 4, 2025
Updated: Feb 12, 2025
CWE ID 922
Summary
CVE-2025-20886 is a vulnerability affecting the softsim TA software prior to the SMR Jan-2025 Release 1. This issue arises due to the inclusion of sensitive information in test code. A local privileged attacker can exploit this vulnerability to obtain a test key, potentially gaining unauthorized access to protected data or functionality. This oversight in the testing environment could pose a significant risk to system security. Organizations using softsim TA are advised to upgrade to the latest release as soon as possible to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Samsung Android
Affected Vendors
- Samsung