CVE-2025-47383
7.2Qualcomm · Snapdragon 5G Fixed Wireless Access Platform and various LTE Modems
A weak configuration in Qualcomm Snapdragon and LTE modem products can result in a missing cryptographic step during VoWiFi call initiation from a User Equipment device.
Executive summary
A missing cryptographic step in Qualcomm hardware products may allow an authenticated attacker to compromise the integrity or confidentiality of Voice over Wi-Fi communications.
Vulnerability
This vulnerability is a configuration error categorized as CWE-325, involving a missing cryptographic step when a Voice over Wi-Fi call is triggered. Per the CVSS vector (PR:H), this attack requires high privileges to execute.
Business impact
The exploitation of this flaw could lead to unauthorized access to sensitive voice traffic or potential manipulation of communication sessions. With a CVSS score of 7.2, this vulnerability represents a high risk to organizational data privacy and operational integrity for systems relying on these specific Qualcomm components.
Remediation
Immediate Action: Consult the official Qualcomm security bulletin for March 2026 to identify specific firmware updates or configuration changes required for your hardware.
Proactive Monitoring: Review system and network logs for unusual VoWiFi connection attempts or irregularities in cryptographic handshake processes.
Compensating Controls: Ensure that all voice traffic is encapsulated within secure VPN tunnels or TLS-protected channels to provide defense-in-depth against potential interception.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential impact on communication security, organizations using the identified Qualcomm hardware must prioritize reviewing the vendor security bulletin. Administrators should apply recommended firmware updates as soon as they are made available to ensure the integrity of the cryptographic implementation.