CVE-2025-47392
8.8Qualcomm · Snapdragon 5G Fixed Wireless Access Platform and related chipsets
A memory corruption vulnerability exists in Qualcomm Snapdragon products due to an integer overflow when processing satellite data files with invalid signature offsets.
Executive summary
A critical memory corruption vulnerability in various Qualcomm Snapdragon chipsets poses a significant risk of system compromise or denial of service through malicious satellite data files.
Vulnerability
This is an integer overflow (CWE-190) occurring during the decoding of satellite data files. The flaw allows an unauthenticated, adjacent attacker to trigger memory corruption, potentially leading to code execution or system instability.
Business impact
The vulnerability carries a CVSS score of 8.8, reflecting its potential for total impact on system confidentiality, integrity, and availability. Successful exploitation could allow an attacker to gain control over affected wireless networking hardware, potentially facilitating unauthorized network access or persistent denial of service across critical infrastructure components.
Remediation
Immediate Action: Review the official Qualcomm April 2026 security bulletin and apply the relevant firmware or driver updates as soon as they become available for your specific hardware configuration.
Proactive Monitoring: Monitor network traffic for unusual patterns or malformed data packets directed at satellite communication interfaces.
Compensating Controls: Restrict access to affected devices to trusted network segments and implement robust physical or logical access controls to limit the exposure of satellite data processing interfaces to unauthorized entities.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the nature of the affected hardware, which is often deployed in critical communications roles, organizations must treat this vulnerability with high priority. We recommend establishing a patch management window immediately upon the release of vendor-specific firmware updates to mitigate the risk of memory corruption and potential remote exploitation.