CVE-2025-47328
7.5Qualcomm · Snapdragon (FastConnect 7800, Immersive Home Platform, IPQ Series)
A buffer over-read vulnerability in Qualcomm Snapdragon platforms allows unauthenticated remote attackers to trigger a denial of service via malformed power control requests.
Executive summary
A critical denial of service vulnerability in Qualcomm Snapdragon hardware allows unauthenticated attackers to crash affected devices by sending specially crafted power control requests.
Vulnerability
This is a buffer over-read (CWE-126) vulnerability occurring during the processing of power control requests. An unauthenticated attacker can exploit this via the network to force the system into a denial of service state.
Business impact
The vulnerability carries a CVSS score of 7.5, indicating a high severity risk due to the ease of exploitation. Successful exploitation results in system instability or a complete denial of service, which can cause significant operational downtime for network infrastructure and connected devices relying on these Qualcomm chipsets.
Remediation
Immediate Action: Review the official Qualcomm September 2025 security bulletin and apply the relevant firmware or driver updates provided by your specific device manufacturer.
Proactive Monitoring: Monitor network traffic for unusual or malformed packets directed at power control interfaces and watch for unexpected device reboots or service outages.
Compensating Controls: Implement network segmentation to restrict access to management interfaces and utilize intrusion detection systems to identify traffic patterns consistent with malformed power control requests.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Given the potential for remote denial of service, organizations utilizing the identified Qualcomm hardware should prioritize vendor patch deployment. Administrators must track firmware updates through their respective hardware vendors, as Qualcomm provides the chipset-level fix which must be integrated into end-user device software. Immediate patching is necessary to ensure the continued availability of critical network infrastructure.