CVE-2025-24857

7.6

U-Boot and Qualcomm · Universal Boot Loader and various IPQ-series chips

Improper access control in U-Boot and specific Qualcomm chips allows physical access to trigger arbitrary code execution via volatile memory.

Executive summary

A critical vulnerability in U-Boot and Qualcomm chipsets allows local attackers to execute arbitrary code by manipulating volatile boot memory.

Vulnerability

This vulnerability involves improper access control for volatile memory containing boot code. The attack vector is physical, requiring an attacker to have direct access to the device to achieve arbitrary code execution.

Business impact

The potential for arbitrary code execution at the boot level poses a severe risk to device integrity and secure boot chains. Because this allows for total system compromise, it could lead to persistent malware installation, unauthorized data access, and full control over affected hardware. Given the CVSS score of 7.6, this is a high-severity issue that necessitates immediate attention in environments where physical security cannot be guaranteed.

Remediation

Immediate Action: Consult the official CISA ICS advisory (ICSA-25-343-01) for vendor-specific patch guidance and firmware update instructions.

Proactive Monitoring: Monitor for unauthorized physical access to critical infrastructure and review system logs for unexpected boot-time anomalies or integrity failures.

Compensating Controls: Implement strict physical security measures to restrict access to hardware interfaces and ensure that devices are stored in secure, tamper-evident environments.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability represents a significant risk to the integrity of the boot process for the affected Qualcomm-based hardware. Administrators should prioritize identifying vulnerable devices within their infrastructure and coordinate with hardware vendors to obtain and deploy the necessary firmware updates as soon as they become available.

Sources