CVE-2025-47383

7.2

Qualcomm · Snapdragon 5G Fixed Wireless Access Platform and various LTE Modems

A weak configuration in Qualcomm Snapdragon and LTE modem products can result in a missing cryptographic step during VoWiFi call initiation from a User Equipment device.

Executive summary

A missing cryptographic step in Qualcomm hardware products may allow an authenticated attacker to compromise the integrity or confidentiality of Voice over Wi-Fi communications.

Vulnerability

This vulnerability is a configuration error categorized as CWE-325, involving a missing cryptographic step when a Voice over Wi-Fi call is triggered. Per the CVSS vector (PR:H), this attack requires high privileges to execute.

Business impact

The exploitation of this flaw could lead to unauthorized access to sensitive voice traffic or potential manipulation of communication sessions. With a CVSS score of 7.2, this vulnerability represents a high risk to organizational data privacy and operational integrity for systems relying on these specific Qualcomm components.

Remediation

Immediate Action: Consult the official Qualcomm security bulletin for March 2026 to identify specific firmware updates or configuration changes required for your hardware.

Proactive Monitoring: Review system and network logs for unusual VoWiFi connection attempts or irregularities in cryptographic handshake processes.

Compensating Controls: Ensure that all voice traffic is encapsulated within secure VPN tunnels or TLS-protected channels to provide defense-in-depth against potential interception.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential impact on communication security, organizations using the identified Qualcomm hardware must prioritize reviewing the vendor security bulletin. Administrators should apply recommended firmware updates as soon as they are made available to ensure the integrity of the cryptographic implementation.

More Qualcomm CVEs

Sources