ZeroHour

CVE-2026-25294

mass

Buffer over-read in Qualcomm WLAN frame parsing causes transient denial of service

CVSS 3.1
7.4 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-25294 is a buffer over-read (CWE-126) in a Qualcomm WLAN component that occurs while parsing a frame during channel usage. An attacker positioned in adjacent radio range (e.g., a nearby Wi-Fi peer) can send a specially crafted frame that triggers the over-read with no privileges or user interaction required. The result is high availability impact only: a transient denial of service of the wireless component, with no confidentiality or integrity loss and no evidence of code execution. Devices containing the affected Qualcomm WLAN component are exposed; the source data does not identify specific chipsets or firmware versions. Exploitation status is currently clean: the flaw is not in CISA KEV and no public proof-of-concept is known.

What to do: No fixed versions are listed in the source data; check Qualcomm's product security bulletin and your device OEM's/Android security bulletin for the fix mapped to CVE-2026-25294 and apply firmware updates when released. Because the attack vector is adjacent (nearby radio range), risk concentrates on Wi-Fi clients and access points within attacker proximity; the DoS is transient, so repeated exposure rather than a single frame is the practical concern. Monitor Qualcomm advisories for the affected chipset identifiers to confirm whether your fleet is in scope.

Affected
Qualcomm
Estimated exposure
massplausibly >1M devices worldwide (Qualcomm Wi-Fi silicon is ubiquitous in Android handsets and IoT devices), though the affected subset is undisclosed — Qualcomm WLAN firmware ships in hundreds of millions to billions of Android smartphones, access points, and IoT devices, so even a partial subset of affected chipsets likely exceeds one million units; the source data provides no…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Transient DOS while parsing frame during channel usage.

Weakness
CWE-126
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.