CVE-2025-20934
MEDIUMDescription
Improper access control in Sticker Center prior to SMR Apr-2025 Release 1 allows local attackers to access image files with system privilege.
Is your site exposed to CVE-2025-20934?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
| samsung | android |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-20934? +
How severe is CVE-2025-20934? +
What products are affected by CVE-2025-20934? +
How do I check if I'm vulnerable to CVE-2025-20934? +
Related Vulnerabilities
Android based smartphones from vendors such as Ulefone and Krüger&Matz contain "com.pri.factorytest" application preloaded onto devices during manufacturing process. The …
An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code …
An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code …
Bluebird devices contain a pre-loaded kiosk application. This application exposes an unsecured service provider "com.bluebird.kiosk.launcher.IpartnerKioskRemoteService". A local attacker can bind …
Bluebird devices contain a pre-loaded file manager application. This application exposes an unsecured service provider "com.bluebird.system.koreanpost.IsdcardRemoteService". A local attacker can …
Bluebird devices contain a pre-loaded barcode scanner application. This application exposes an unsecured broadcast receiver "kr.co.bluebird.android.bbsettings.BootReceiver". A local attacker can …