Samsung Exynos Modem and Processor Denial-of-Service Vulnerability via RRC Setup Procedure

Vulnerability

A denial-of-service vulnerability has been identified in Samsung mobile processors and modems, specifically in the Exynos 5G modem and processor series, including Exynos 9820, 9825, 980, 990, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W1000, Modem 5123, Modem 5300, and Modem 5400. The issue arises because the User Equipment (UE) does not limit the number of attempts for the Radio Resource Control (RRC) Setup procedure in 5G Standalone (SA) mode. This oversight can be exploited to create a battery-drain attack, causing unnecessary power consumption and potentially leading to premature device shutdown.

Impact

Exploitation of this vulnerability causes excessive battery drain on affected devices, which can lead to unexpected shutdowns.

Reproduction

The vulnerability can be reproduced by connecting a smartphone or device with a vulnerable Exynos processor or modem to a rogue 5G base station that is set up to repeatedly send RRC Setup requests. This can be done using the 5Ghoul tool, which automates the process of creating the rogue base station and launching the attack. Once the device is connected to the base station, the attack will drain the device's battery by keeping the 5G connection active without interruption.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
2.5
exploitability
6.0
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.