Vulnerability Details CVE-2025-20939
Improper authorization in wireless download protocol in Galaxy Watch prior to SMR Apr-2025 Release 1 allows physical attackers to update device unique identifier of Watch devices.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 18.4%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2025-20939
-
cpe:2.3:h:samsung:galaxy_watch:-
-
cpe:2.3:h:samsung:galaxy_watch_4:-
-
cpe:2.3:h:samsung:galaxy_watch_4_classic:-
-
cpe:2.3:h:samsung:galaxy_watch_5:-
-
cpe:2.3:h:samsung:galaxy_watch_5_pro:-
-
cpe:2.3:h:samsung:galaxy_watch_6:-
-
cpe:2.3:h:samsung:galaxy_watch_6_classic:-
-
cpe:2.3:h:samsung:galaxy_watch_7:-
-
cpe:2.3:h:samsung:galaxy_watch_fe:-
-
cpe:2.3:h:samsung:galaxy_watch_ultra:-
-
cpe:2.3:o:samsung:wear_os:5.0