CVE-2025-47324
7.5Qualcomm · QCA7005
A vulnerability in Qualcomm QCA7005 powerline communication hardware allows for information disclosure via unauthorized access or modification of the PIB file.
Executive summary
A critical information disclosure vulnerability in Qualcomm QCA7005 powerline devices allows unauthenticated remote attackers to access or modify sensitive PIB files.
Vulnerability
This vulnerability involves the exposure of sensitive information through metadata, specifically regarding the Parameter Information Block (PIB) file. The attack vector is network-based (AV:N) and requires no authentication (PR:N) or user interaction (UI:N), allowing remote actors to potentially compromise data confidentiality.
Business impact
The ability for an unauthenticated remote attacker to access or modify PIB files poses a significant risk to the integrity and confidentiality of powerline network configurations. Given the CVSS score of 7.5, this high-severity flaw could lead to unauthorized device manipulation, potential service degradation, or the leakage of sensitive operational metadata, which may facilitate further network exploitation.
Remediation
Immediate Action: Consult the official Qualcomm August 2025 security bulletin to identify and apply the necessary firmware updates or configuration changes provided by the vendor.
Proactive Monitoring: Monitor network traffic for unusual access patterns or requests targeting PIB file management functions on affected powerline devices.
Compensating Controls: Implement network segmentation to isolate powerline communication segments from public-facing or untrusted network zones to restrict remote access to the vulnerable interface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations utilizing Qualcomm QCA7005 hardware must prioritize this advisory due to the lack of required authentication for exploitation. Administrators should verify their current firmware status against the Qualcomm August 2025 security bulletin and apply all recommended patches immediately to prevent unauthorized access to sensitive device configuration files.