VYPR
Unrated severityNVD Advisory· Published Apr 7, 2020· Updated Aug 5, 2024

CVE-2017-18650

CVE-2017-18650

Description

An issue was discovered on Samsung mobile devices with N(7.x) software. There is a WifiStateMachine IllegalArgumentException and reboot if a malformed wpa_supplicant.conf is read. The Samsung ID is SVE-2017-9828 (October 2017).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A malformed wpa_supplicant.conf file on Samsung N(7.x) devices triggers a WifiStateMachine IllegalArgumentException and system reboot.

Vulnerability

An issue in Samsung mobile devices running N(7.x) software (Android 7.x) allows a malformed wpa_supplicant.conf file to cause a WifiStateMachine IllegalArgumentException and a subsequent device reboot. The vulnerability was identified in October 2017 with Samsung ID SVE-2017-9828 [1].

Exploitation

An attacker requires the ability to write or influence the contents of the wpa_supplicant.conf file on the device, typically necessitating local access or a previously installed malicious application with sufficient permissions to modify system configuration files. The attacker crafts a malformed wpa_supplicant.conf that, when parsed by the Android Wi-Fi stack, causes an unhandled IllegalArgumentException in the WifiStateMachine state machine.

Impact

Successful exploitation results in an immediate system reboot, causing a denial of service (DoS). No other compromise of confidentiality, integrity, or additional privileges is reported.

Mitigation

Samsung addressed this issue in a security update released as part of their monthly maintenance releases, likely included in the Samsung Mobile Security Update for October 2017 or later. Users should apply the latest security patch for their device model via Samsung's update mechanism [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.