CVE-2025-20942
CVSS 3.1 Score 4.4 of 10 (medium)
Details
Published Apr 8, 2025
Summary
CVE-2025-20942 is a vulnerability affecting DeviceIdService in certain devices. The issue lies in the Broadcast Receiver component, which fails to properly verify the intent of incoming broadcasts before SMR Apr-2025 Release 1. This weakness enables local attackers to manipulate the OAID (Originating Activation ID) reset, potentially leading to unauthorized access or privilege escalation. This vulnerability poses a risk to device security and requires immediate attention from device manufacturers to release a patch or update.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.