CVE-2025-47326
7.5Qualcomm · Snapdragon (AR8035, CSR8811, FastConnect 6900, FastConnect 7800, Immersive Home 214/216/316/318 Platforms)
A buffer over-read vulnerability in Qualcomm Snapdragon products allows for a denial of service condition when processing command data during power control operations.
Executive summary
A buffer over-read vulnerability within various Qualcomm Snapdragon platforms could allow an unauthenticated attacker to trigger a denial of service condition.
Vulnerability
This is a buffer over-read (CWE-126) vulnerability occurring during the handling of command data in power control processing, which can be triggered by an unauthenticated attacker.
Business impact
The vulnerability carries a CVSS score of 7.5, indicating a high severity due to the potential for service disruption. Successful exploitation results in a denial of service, which can lead to significant operational downtime for affected networking and communication hardware, impacting organizational productivity and availability.
Remediation
Immediate Action: Consult the official Qualcomm September 2025 security bulletin for available firmware updates and apply them to all vulnerable platforms immediately.
Proactive Monitoring: Monitor system logs for unexpected crashes, reboots, or irregularities in power control command processing that may indicate an attempted exploit.
Compensating Controls: Ensure that affected devices are isolated within trusted network segments to limit exposure to untrusted traffic until patches are applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the potential for widespread service disruption across Snapdragon-based infrastructure, organizations should prioritize reviewing their hardware inventory against the affected list. Apply vendor-supplied firmware updates as soon as they become available to mitigate the risk of denial of service attacks.