CVE-2025-27073

7.5

Qualcomm · Snapdragon

A reachable assertion vulnerability exists in various Qualcomm Snapdragon products, allowing an unauthenticated attacker to trigger a denial of service during the creation of an NDP instance.

Executive summary

A critical denial of service vulnerability in Qualcomm Snapdragon hardware components enables unauthenticated attackers to crash system processes via a reachable assertion.

Vulnerability

The vulnerability is a reachable assertion (CWE-617) triggered during the creation of an NDP instance. It is exploitable by an unauthenticated attacker over the network, as indicated by the CVSS vector AV:N/PR:N/UI:N.

Business impact

The ability for an unauthenticated attacker to cause a denial of service poses a significant risk to system availability and operational continuity. With a CVSS score of 7.5, this flaw represents a high-severity risk that could lead to service outages in affected networking and connectivity hardware. Organizations relying on these Snapdragon platforms may face unplanned downtime, impacting business-critical communication or data transfer processes.

Remediation

Immediate Action: Consult the official Qualcomm August 2025 security bulletin at the provided reference link to identify specific firmware updates or configuration changes required for your hardware models.

Proactive Monitoring: Monitor system logs for unexpected reboots or service crashes that correlate with network traffic spikes, which may indicate exploitation attempts.

Compensating Controls: Ensure that affected devices are isolated behind robust firewalls to restrict unauthorized network access to management or NDP-related interfaces.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for service disruption, administrators must prioritize reviewing the Qualcomm security bulletin for available patches. Because the vulnerability is reachable over the network without authentication, timely application of vendor-supplied firmware updates is essential to prevent potential denial of service attacks against affected infrastructure.

More Qualcomm CVEs

Sources