CVE-2025-21452
7.5Qualcomm · Snapdragon (315 5G IoT Modem, AR8035, FastConnect 6200, FastConnect 6700, FastConnect 6800, FastConnect 6900, FSM10055, QCA6174A)
A reachable assertion vulnerability in certain Qualcomm Snapdragon modem and connectivity products allows for a denial of service via a specially crafted LTE random-access response.
Executive summary
A critical denial of service vulnerability in specific Qualcomm Snapdragon components allows unauthenticated remote attackers to crash the affected modem hardware.
Vulnerability
This is a reachable assertion (CWE-617) occurring when the system processes a random-access response (RAR) containing an invalid PDU length on an LTE network, which can be triggered by an unauthenticated attacker.
Business impact
The vulnerability carries a CVSS score of 7.5, reflecting a High severity impact due to the potential for complete service denial. Successful exploitation results in the inability of the affected device to maintain network connectivity, which could cause significant operational disruption in IoT and telecommunications environments relying on these modems.
Remediation
Immediate Action: Review the August 2025 Qualcomm Security Bulletin and apply the recommended firmware updates provided by your specific hardware vendor.
Proactive Monitoring: Monitor device logs for unexpected modem restarts or connectivity drops that correlate with LTE network traffic patterns.
Compensating Controls: Ensure device firmware is isolated behind secure network gateways where possible and monitor for anomalous packet structures within the radio access network environment.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for remote denial of service on critical infrastructure and IoT components, this vulnerability represents a significant stability risk. Organizations utilizing affected Qualcomm Snapdragon hardware should prioritize the deployment of vendor-supplied firmware updates to address the underlying assertion failure and ensure continued network availability.