
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-20999 is an improper authorization vulnerability in the Wi-Fi password storage mechanism of Samsung Galaxy Tablets, classified under CWE-863 (Incorrect Authorization). It allows secondary users with physical access to a device to view the device owner's saved Wi-Fi passwords without proper authorization. The vulnerability affects Samsung Android versions 13, 14, and 15 prior to the SMR Jul-2025 Release 1. It was published on July 8, 2025, with a patch released on July 14, 2025. The CVSS v3.1 base score is 2.1 (Low) per NVD, though ENISA's EUVD rates it at 4.1 (Medium) (Samsung Security, ENISA EUVD).
The root cause is CWE-863 (Incorrect Authorization) — the Galaxy Tablet's Wi-Fi settings component fails to enforce proper access controls between the device owner's profile and secondary user profiles. A secondary user with low-level privileges and physical access to the device can navigate to the Wi-Fi settings and retrieve the owner's saved network credentials without requiring owner-level authorization. The attack vector is physical (AV:P), requires low privileges (PR:L), and no user interaction from the owner, making it exploitable by any secondary account holder on a shared device (Samsung Security, ENISA EUVD).
Successful exploitation allows an unauthorized secondary user to read the device owner's saved Wi-Fi network credentials, resulting in a low confidentiality impact. There is no integrity or availability impact. While the direct impact is limited to credential disclosure, exposed Wi-Fi passwords could enable unauthorized network access, potentially facilitating further network-based reconnaissance or lateral movement within the owner's home or corporate network (Samsung Security, ENISA EUVD).
There is no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been reported. The EPSS score is approximately 0.015% (0.000150), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires physical access to the device and an existing secondary user account, significantly limiting the attack surface (Samsung Security, ENISA EUVD).
Samsung has addressed this vulnerability in the SMR Jul-2025 Release 1 for Android versions 13, 14, and 15. Users should apply the July 2025 Samsung Security Monthly Release update as soon as it is available for their device. As interim workarounds, administrators and device owners should restrict physical device access to trusted individuals, regularly review and remove unnecessary secondary user accounts, and consider disabling secondary user accounts when not in use (Samsung Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."