CVE-2021-25434 is a critical improper input validation vulnerability affecting the Tizen bootloader prior to the JUL-2021 firmware update. This flaw allows for arbitrary code execution by manipulating the 'param' partition during wireless firmware download mode. With a CVSS score of 9.8, it presents a severe risk, enabling unauthenticated attackers to achieve complete compromise of affected Linux Tizen devices with high impact on confidentiality, integrity, and availability. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and there's minimal community discussion or media coverage, the potential for a critical impact remains high.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.5CPE matchmatch criteria | cpe:2.3:o:linux:tizen:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.