CVE Vulnerabilities

CVE-2025-20895

Published: Feb 04, 2025 | Modified: Jul 17, 2025
CVSS 3.x
4.6
MEDIUM
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Authentication Bypass Using an Alternate Path in Galaxy Store prior to version 4.5.87.6 allows physical attackers to install arbitrary applications to bypass restrictions of Setupwizard.

Affected Software

NameVendorStart VersionEnd Version
Galaxy_storeSamsung*4.5.87.6 (excluding)

References