CVE-2018-16270: Samsung Galaxy Gear Firmware
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
Samsung Galaxy Gear series before build RE2 includes the hcidump utility with no privilege or permission restriction. This allows an unprivileged process to dump Bluetooth HCI packets to an arbitrary file path.
Affected products
- Samsung Galaxy Gear Firmware: before re2 (fixed in re2)
- Samsung Gear 2 Firmware: before re2 (fixed in re2)
- Samsung Gear Fit 2 Firmware: before re2 (fixed in re2)
- Samsung Gear Fit 2 Pro Firmware: before re2 (fixed in re2)
- Samsung Gear Fit Firmware: before re2 (fixed in re2)
- Samsung Gear Live Firmware: before re2 (fixed in re2)
- Samsung Gear s2 Firmware: before re2 (fixed in re2)
- Samsung Gear s3 Firmware: before re2 (fixed in re2)
- Samsung Gear S Firmware: before re2 (fixed in re2)
- Samsung Gear Sport Firmware: before re2 (fixed in re2)
Published 2020-01-22. Last modified 2026-06-17.