Transient DOS while processing power control requests with invalid antenna or stream values
Description
Transient DOS while processing power control requests with invalid antenna or stream values
AI Analyst Comment
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Qualcomm
PRODUCT: Snapdragon (FastConnect 7800, Immersive Home Platform, IPQ Series)
AFFECTED_VERSIONS: FastConnect 7800, Immersive Home 3210 Platform, Immersive Home 326 Platform, IPQ5300, IPQ5302, IPQ5312, IPQ5332, IPQ5424
CONFIDENCE: high
MISSING: patch, technical_details
SOURCES_JSON: [{"url":"https://docs.qualcomm.com/product/publicresources/securitybulletin/september-2025-bulletin.html","name":null,"tags":[]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T14:11:41.438Z
---END_METADATA---
Description Summary:
A buffer over-read vulnerability in Qualcomm Snapdragon platforms allows unauthenticated remote attackers to trigger a denial of service via malformed power control requests.
Executive Summary:
A critical denial of service vulnerability in Qualcomm Snapdragon hardware allows unauthenticated attackers to crash affected devices by sending specially crafted power control requests.
Vulnerability Details
CVE-ID: CVE-2025-47328
Affected Software: Qualcomm Snapdragon
Affected Versions: FastConnect 7800, Immersive Home 3210 Platform, Immersive Home 326 Platform, IPQ5300, IPQ5302, IPQ5312, IPQ5332, IPQ5424
Vulnerability: This is a buffer over-read (CWE-126) vulnerability occurring during the processing of power control requests. An unauthenticated attacker can exploit this via the network to force the system into a denial of service state.
Business Impact
The vulnerability carries a CVSS score of 7.5, indicating a high severity risk due to the ease of exploitation. Successful exploitation results in system instability or a complete denial of service, which can cause significant operational downtime for network infrastructure and connected devices relying on these Qualcomm chipsets.
Remediation Plan
Immediate Action: Review the official Qualcomm September 2025 security bulletin and apply the relevant firmware or driver updates provided by your specific device manufacturer.
Proactive Monitoring: Monitor network traffic for unusual or malformed packets directed at power control interfaces and watch for unexpected device reboots or service outages.
Compensating Controls: Implement network segmentation to restrict access to management interfaces and utilize intrusion detection systems to identify traffic patterns consistent with malformed power control requests.
Exploitation Status
Public Exploit Available: No (exploit_available: unknown)
Analyst Notes: As of September 25, 2025, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is considered inherently exploitable due to the lack of required authentication, though no weaponized exploits have been observed.
Analyst Recommendation
Given the potential for remote denial of service, organizations utilizing the identified Qualcomm hardware should prioritize vendor patch deployment. Administrators must track firmware updates through their respective hardware vendors, as Qualcomm provides the chipset-level fix which must be integrated into end-user device software. Immediate patching is necessary to ensure the continued availability of critical network infrastructure.