ZeroHour

CVE-2026-25275

mass

Transient Wi-Fi DoS in Qualcomm WLAN via malformed FILS authentication frames

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-25275 is an out-of-bounds read (CWE-126) in the Qualcomm WLAN component's processing of IEEE 802.11 authentication frames that carry a FILS (Fast Initial Link Setup, 802.11ai) information element. An attacker within Wi-Fi radio range can trigger it by sending an unauthenticated authentication frame whose FILS information element header length fields are invalid, causing the parser to read past the frame data. The result is a transient denial of service (typically a Wi-Fi subsystem crash and re-initialization); there is no confidentiality or integrity impact and no code execution, reflected in the CVSS 3.1 vector (C:N/I:N/A:H, score 7.5 high). Devices using the affected Qualcomm WLAN software, such as Snapdragon-based and other Qualcomm-chipset Wi-Fi products, are exposed, though the specific affected SoC/version list was not included in the available data. No exploitation is known: the flaw is not in CISA KEV, no public proof-of-concept exists, and no in-the-wild abuse has been reported.

What to do: Apply the WLAN firmware/host driver fix from Qualcomm's security bulletin as distributed through your device vendor (e.g., Android or Windows OEM security updates), and check your device or chipset model against Qualcomm's advisory for confirmation. Because the attack is over the air and requires no credentials, patching is the only practical fix; organizations with wireless IDS/WIPS can watch for anomalous FILS authentication frames. Impact is transient, so affected devices recover after the Wi-Fi subsystem restarts or reconnects.

Affected
Qualcomm WLAN component (Wi-Fi firmware/host driver in Snapdragon-based and other Qualcomm-chipset devices)
Estimated exposure
masspotentially billions of devices (upper bound; Qualcomm Wi-Fi silicon ships in hundreds of millions of smartphones and consumer/IoT devices), with only… — Qualcomm's Wi-Fi chipsets are among the most widely deployed in smartphones and embedded devices, and no affected-chip list was provided in the data, so this is a best-effort upper-bound estimate; practical exposure is limited to devices…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Transient DOS when processing authentication frames with invalid FILS information element header lengths.

Weakness
CWE-126
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.