CVE-2026-25275
massTransient Wi-Fi DoS in Qualcomm WLAN via malformed FILS authentication frames
CVE-2026-25275 is an out-of-bounds read (CWE-126) in the Qualcomm WLAN component's processing of IEEE 802.11 authentication frames that carry a FILS (Fast Initial Link Setup, 802.11ai) information element. An attacker within Wi-Fi radio range can trigger it by sending an unauthenticated authentication frame whose FILS information element header length fields are invalid, causing the parser to read past the frame data. The result is a transient denial of service (typically a Wi-Fi subsystem crash and re-initialization); there is no confidentiality or integrity impact and no code execution, reflected in the CVSS 3.1 vector (C:N/I:N/A:H, score 7.5 high). Devices using the affected Qualcomm WLAN software, such as Snapdragon-based and other Qualcomm-chipset Wi-Fi products, are exposed, though the specific affected SoC/version list was not included in the available data. No exploitation is known: the flaw is not in CISA KEV, no public proof-of-concept exists, and no in-the-wild abuse has been reported.
What to do: Apply the WLAN firmware/host driver fix from Qualcomm's security bulletin as distributed through your device vendor (e.g., Android or Windows OEM security updates), and check your device or chipset model against Qualcomm's advisory for confirmation. Because the attack is over the air and requires no credentials, patching is the only practical fix; organizations with wireless IDS/WIPS can watch for anomalous FILS authentication frames. Impact is transient, so affected devices recover after the Wi-Fi subsystem restarts or reconnects.
| Qualcomm WLAN component (Wi-Fi firmware/host driver in Snapdragon-based and other Qualcomm-chipset devices) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
- Weakness
- CWE-126
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.