CVE-2025-47326

7.5

Qualcomm · Snapdragon (AR8035, CSR8811, FastConnect 6900, FastConnect 7800, Immersive Home 214/216/316/318 Platforms)

A buffer over-read vulnerability in Qualcomm Snapdragon products allows for a denial of service condition when processing command data during power control operations.

Executive summary

A buffer over-read vulnerability within various Qualcomm Snapdragon platforms could allow an unauthenticated attacker to trigger a denial of service condition.

Vulnerability

This is a buffer over-read (CWE-126) vulnerability occurring during the handling of command data in power control processing, which can be triggered by an unauthenticated attacker.

Business impact

The vulnerability carries a CVSS score of 7.5, indicating a high severity due to the potential for service disruption. Successful exploitation results in a denial of service, which can lead to significant operational downtime for affected networking and communication hardware, impacting organizational productivity and availability.

Remediation

Immediate Action: Consult the official Qualcomm September 2025 security bulletin for available firmware updates and apply them to all vulnerable platforms immediately.

Proactive Monitoring: Monitor system logs for unexpected crashes, reboots, or irregularities in power control command processing that may indicate an attempted exploit.

Compensating Controls: Ensure that affected devices are isolated within trusted network segments to limit exposure to untrusted traffic until patches are applied.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the potential for widespread service disruption across Snapdragon-based infrastructure, organizations should prioritize reviewing their hardware inventory against the affected list. Apply vendor-supplied firmware updates as soon as they become available to mitigate the risk of denial of service attacks.

More Qualcomm CVEs

Sources