CVE-2015-7888 describes a directory traversal vulnerability in the WifiHs20UtilityService of the Samsung S6 Edge (firmware LRX22G.G925VVRU1AOE2). This flaw allows a remote attacker to overwrite or create arbitrary files as a system-level user. The attack involves crafting a specially named file with a ".." (dot dot) sequence, compressing it into a "cred.zip" file, and having it downloaded to the device's /sdcard/Download directory. The vulnerability carries a CVSS v3 score of 7.5 (High), indicating a severe risk. It is remotely exploitable with low attack complexity and no user interaction required, leading to a high impact on integrity (I:H) by allowing arbitrary file manipulation. Confidentiality and availability are not directly impacted. While the vulnerability received media coverage and some community discussion, there is no evidence of active exploitation (KEV: No) and no public exploit code available in Metasploit, Nuclei, or ExploitDB. Its EPSS score is low, suggesting a low likelihood of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
g925vvru1aoe2CPE matchmatch criteria | cpe:2.3:o:samsung:galaxy_s6_edge_firmware:g925vvru1aoe2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.