CVE-2025-21477
7.5Qualcomm · Snapdragon (315 5G IoT Modem, AR8035, FastConnect 6200, FastConnect 6700, FastConnect 6800, FastConnect 6900, FastConnect 7800, QCA6391)
An improper input validation vulnerability in Qualcomm Snapdragon products allows unauthenticated attackers to cause a denial of service via malformed CCCH data.
Executive summary
A high-severity denial of service vulnerability in Qualcomm Snapdragon modem and connectivity hardware poses a significant risk to network availability.
Vulnerability
This flaw stems from improper input validation (CWE-20) within the CCCH processing logic. Unauthenticated, network-adjacent attackers can trigger this state by sending data with an invalid length, resulting in a denial of service.
Business impact
The CVSS score of 7.5 reflects a high risk due to the potential for complete service disruption. Successful exploitation results in system instability or crashes, which could lead to significant operational downtime for affected IoT and mobile communication devices.
Remediation
Immediate Action: Review the official Qualcomm security bulletin for August 2025 to identify and apply the necessary firmware or driver updates for the specific affected hardware components.
Proactive Monitoring: Monitor network traffic for malformed packets or unusual CCCH traffic patterns that may indicate attempts to trigger this vulnerability.
Compensating Controls: Ensure devices are isolated within secure network segments to limit exposure to untrusted network traffic where possible.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical nature of modem and connectivity firmware in maintaining system uptime, organizations should prioritize the identification of affected hardware within their inventory. Apply vendor-provided security patches immediately upon availability to mitigate the risk of denial-of-service attacks.