CVE-2025-27066

7.5

Qualcomm · Snapdragon

A reachable assertion vulnerability in Qualcomm Snapdragon products allows unauthenticated remote attackers to trigger a denial of service condition via malicious ANQP messages.

Executive summary

A high-severity denial of service vulnerability in various Qualcomm Snapdragon components allows unauthenticated remote attackers to disrupt system availability.

Vulnerability

This flaw is a reachable assertion (CWE-617) triggered during the processing of Access Network Query Protocol (ANQP) messages. The vulnerability is remotely exploitable by an unauthenticated attacker, requiring no user interaction.

Business impact

The exploitation of this vulnerability results in a denial of service, which can cause significant operational disruption for devices utilizing the affected modems and hardware. With a CVSS score of 7.5, the vulnerability is classified as high severity, reflecting the ease of remote exploitation and the potential for complete loss of service availability for the impacted hardware.

Remediation

Immediate Action: Review the official Qualcomm August 2025 security bulletin for firmware updates and apply them to all vulnerable devices as a priority.

Proactive Monitoring: Monitor device logs and network traffic for unusual volumes of ANQP traffic or unexpected system reboots that may indicate exploitation attempts.

Compensating Controls: Ensure that network segmentation is in place to limit exposure of management interfaces to untrusted networks, which may reduce the attack surface for remote exploitation.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the remote, unauthenticated nature of this vulnerability, organizations must prioritize the identification of affected hardware within their infrastructure. Administrators should follow the Qualcomm security bulletin for specific patch availability and deploy firmware updates immediately upon release to prevent potential service disruptions.

More Qualcomm CVEs

Sources