High severity7.5NVD Advisory· Published Jan 22, 2020· Updated Jun 17, 2026
CVE-2018-16270
CVE-2018-16270
Description
Samsung Galaxy Gear series before build RE2 includes the hcidump utility with no privilege or permission restriction. This allows an unprivileged process to dump Bluetooth HCI packets to an arbitrary file path.
Affected products
12- Samsung/Galaxy Gear seriesdescription
- Range: <RE2
- cpe:2.3:o:samsung:galaxy_gear_firmware:*:*:*:*:*:*:*:*Range: <re2
- cpe:2.3:o:samsung:gear_fit_2_pro_firmware:*:*:*:*:*:*:*:*Range: <re2
Patches
Vulnerability mechanics
References
2- media.defcon.org/DEF%20CON%2026/DEF%20CON%2026%20presentations/Dongsung%20Kim%20and%20Hyoung%20Kee%20Choi%20-%20Updated/DEFCON-26-Dongsung-Kim-and-Hyoung-Kee-Choi-Your-Watch-Can-Watch-You-Updated.pdfnvdExploitThird Party Advisory
- www.youtube.com/watchnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.