CVE-2025-54328 is a stack-based buffer overflow in the SMS component of Samsung Mobile Processor, Wearable Processor, and Modem Exynos chipsets, including Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. The issue occurs while parsing SMS RP-DATA messages, indicating that malformed or oversized RP-DATA input can overwrite stack memory during message handling. Based on the available information, the flaw is in the SMS parsing logic for RP-DATA protocol messages on affected Exynos-based cellular components.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone proof-of-concept for CVE-2025-54328, consisting of a README and one Python script. The Python file, poc_cve_2025_54328.py, is the main entry point and contains all exploit logic. It does not perform live exploitation or radio transmission; instead, it constructs a raw SMS RP-DATA message intended for network-to-mobile delivery and saves it as a binary blob. The core capability is generation of a malformed RP-DATA payload targeting Samsung Exynos/Shannon baseband firmware. The function build_rp_data_overflow() assembles an RP-DATA message by encoding the destination MSISDN into BCD form, creating a TPDU structure, and appending an oversized TP-UD field. The overflow content is a simple repeated 0x41 pattern of configurable size (default 200 bytes), indicating a trigger-only memory corruption PoC rather than a full exploit with ROP chain or shellcode. The script then prints a hex dump, describes the intended attack flow, and writes the crafted message to cve-2025-54328-poc-rpdata.bin. There are no hardcoded IPs, domains used for command-and-control, or network callbacks in the exploit itself. The only URL present is a reference article. The only concrete file artifact is the generated binary output file. Delivery mechanisms are discussed only in documentation/output text: fake BTS setups using OpenBTS or srsRAN with SDR hardware such as USRP or HackRF, SMS gateways with raw PDU access, or direct baseband injection via JTAG/UART. Overall, this is a conceptual wireless/baseband exploit trigger generator, not a complete operational exploit chain.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.