CVE-2025-21079

High7.1Published on November 5, 2025

Improper input validation in Samsung Members prior to version 5.5.01.3 allows remote attackers to connect arbitrary URL and launch arbitrary activity with Samsung Members privilege. User interaction is required for triggering this vulnerability.

CVSS score7.1 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
Vendorssamsung

Affected products

VendorsProductVersions
samsungmembers< 5.5.01.3

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database