CVE-2025-47328

7.5

Qualcomm · Snapdragon (FastConnect 7800, Immersive Home Platform, IPQ Series)

A buffer over-read vulnerability in Qualcomm Snapdragon platforms allows unauthenticated remote attackers to trigger a denial of service via malformed power control requests.

Executive summary

A critical denial of service vulnerability in Qualcomm Snapdragon hardware allows unauthenticated attackers to crash affected devices by sending specially crafted power control requests.

Vulnerability

This is a buffer over-read (CWE-126) vulnerability occurring during the processing of power control requests. An unauthenticated attacker can exploit this via the network to force the system into a denial of service state.

Business impact

The vulnerability carries a CVSS score of 7.5, indicating a high severity risk due to the ease of exploitation. Successful exploitation results in system instability or a complete denial of service, which can cause significant operational downtime for network infrastructure and connected devices relying on these Qualcomm chipsets.

Remediation

Immediate Action: Review the official Qualcomm September 2025 security bulletin and apply the relevant firmware or driver updates provided by your specific device manufacturer.

Proactive Monitoring: Monitor network traffic for unusual or malformed packets directed at power control interfaces and watch for unexpected device reboots or service outages.

Compensating Controls: Implement network segmentation to restrict access to management interfaces and utilize intrusion detection systems to identify traffic patterns consistent with malformed power control requests.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Given the potential for remote denial of service, organizations utilizing the identified Qualcomm hardware should prioritize vendor patch deployment. Administrators must track firmware updates through their respective hardware vendors, as Qualcomm provides the chipset-level fix which must be integrated into end-user device software. Immediate patching is necessary to ensure the continued availability of critical network infrastructure.

More Qualcomm CVEs

Sources