CVE-2025-27065

7.5

Qualcomm · Snapdragon and Networking Platforms

A buffer over-read vulnerability in various Qualcomm Snapdragon and networking products allows for a denial of service via malformed shared-key descriptor frames.

Executive summary

A buffer over-read vulnerability in multiple Qualcomm products enables unauthenticated remote attackers to trigger a denial of service condition.

Vulnerability

The flaw is a buffer over-read (CWE-126) triggered during the processing of a frame containing a malformed shared-key descriptor. An unauthenticated remote attacker can exploit this via the network to cause system instability or a crash.

Business impact

This vulnerability carries a CVSS score of 7.5, classifying it as High severity. The primary business impact is a potential denial of service, which can disrupt critical network operations and infrastructure availability for organizations relying on the affected Qualcomm hardware.

Remediation

Immediate Action: Review the official Qualcomm security bulletin for August 2025 and apply available firmware updates to all affected devices immediately.

Proactive Monitoring: Monitor network infrastructure logs for unusual traffic patterns or frequent device reboots that may indicate exploitation attempts.

Compensating Controls: Utilize network segmentation and hardware-level firewalls to restrict traffic to vulnerable components, limiting the exposure of management interfaces to untrusted sources.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score and the potential for remote denial of service, organizations must treat this vulnerability with urgency. Administrators should prioritize identifying and updating the affected Qualcomm hardware platforms identified in the vendor security bulletin to ensure continued service availability and system integrity.

More Qualcomm CVEs

Sources