CVE-2025-27054

7.8

Qualcomm · Snapdragon Modems

A memory corruption vulnerability exists in various Qualcomm Snapdragon modems due to improper processing of malformed license files during system reboot.

Executive summary

An out-of-bounds write vulnerability in Qualcomm Snapdragon modem firmware could allow a local attacker with low privileges to achieve full system compromise.

Vulnerability

This is an out-of-bounds write (CWE-787) flaw triggered during the processing of a malformed license file during the reboot sequence. The attack vector is local, requiring low privileges to execute.

Business impact

The vulnerability carries a CVSS score of 7.8, indicating a high severity risk. Successful exploitation could lead to full loss of confidentiality, integrity, and availability of the affected modem hardware, potentially resulting in unauthorized code execution and complete system takeover.

Remediation

Immediate Action: Review the official Qualcomm security bulletin for October 2025 to identify and apply the necessary firmware updates for your specific device models.

Proactive Monitoring: Monitor device logs for unexpected reboots or service failures that may indicate an attempt to trigger the corrupted state.

Compensating Controls: Ensure that physical access to hardware is strictly controlled and that only authorized users can initiate system reboots or configuration changes.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the high CVSS score and the nature of the vulnerability affecting low-level modem firmware, administrators should prioritize this update. Locate the relevant firmware patches via the Qualcomm security portal and deploy them to all affected IoT and modem assets to prevent potential unauthorized code execution during the reboot process.

More Qualcomm CVEs

Sources