CVE-2025-21476

Sept. 25, 2025, 4:08 p.m.

7.8
High

Description

Memory corruption when passing parameters to the Trusted Virtual Machine during the handshake.

Product(s) Impacted

Vendor Product Versions
Qualcomm
  • Qcs6490 Firmware
  • Qcs6490
  • Qcs8550 Firmware
  • Qcs8550
  • Qcs9100 Firmware
  • Qcs9100
  • Sg8275 Firmware
  • Sg8275
  • Sg8275p Firmware
  • Sg8275p
  • Sm6650 Firmware
  • Sm6650
  • Sm7635 Firmware
  • Sm7635
  • Sm7675 Firmware
  • Sm7675
  • Sm7675p Firmware
  • Sm7675p
  • Sm8550 Firmware
  • Sm8550
  • Sm8550p Firmware
  • Sm8550p
  • Sm8635 Firmware
  • Sm8635
  • Sm8635p Firmware
  • Sm8635p
  • Sm8650 Firmware
  • Sm8650
  • Sm8650p Firmware
  • Sm8650p
  • Sm8650q Firmware
  • Sm8650q
  • Sm8750 Firmware
  • Sm8750
  • Sm8750p Firmware
  • Sm8750p
  • Sxr2330p Firmware
  • Sxr2330p
  • Qca6391 Firmware
  • Qca6391
  • Qca6698aq Firmware
  • Qca6698aq
  • Qcn9011 Firmware
  • Qcn9011
  • Qcn9012 Firmware
  • Qcn9012
  • Qcn9274 Firmware
  • Qcn9274
  • Wcn3910 Firmware
  • Wcn3910
  • Wcn3950 Firmware
  • Wcn3950
  • Wcn6650 Firmware
  • Wcn6650
  • Wcn6750 Firmware
  • Wcn6750
  • Wcn6755 Firmware
  • Wcn6755
  • Wcn6855 Firmware
  • Wcn6855
  • Wcn6856 Firmware
  • Wcn6856
  • Wcn7850 Firmware
  • Wcn7850
  • Wcn7851 Firmware
  • Wcn7851
  • Wcn7860 Firmware
  • Wcn7860
  • Wcn7861 Firmware
  • Wcn7861
  • Wcn7880 Firmware
  • Wcn7880
  • Wcn7881 Firmware
  • Wcn7881
  • Qcm5430 Firmware
  • Qcm5430
  • Qcm6490 Firmware
  • Qcm6490
  • Qcm8550 Firmware
  • Qcm8550
  • Qcs5430 Firmware
  • Qcs5430
  • Qcs615 Firmware
  • Qcs615
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -

Weaknesses

Common security weaknesses mapped to this vulnerability.

CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.

*CPE(s)

Affected systems and software identified for this CVE.

Type Vendor Product Version Update Edition Language Software Edition Target Software Target Hardware Other Information
o qualcomm qcs6490_firmware - / / / / / / /
h qualcomm qcs6490 - / / / / / / /
o qualcomm qcs8550_firmware - / / / / / / /
h qualcomm qcs8550 - / / / / / / /
o qualcomm qcs9100_firmware - / / / / / / /
h qualcomm qcs9100 - / / / / / / /
o qualcomm sg8275_firmware - / / / / / / /
h qualcomm sg8275 - / / / / / / /
o qualcomm sg8275p_firmware - / / / / / / /
h qualcomm sg8275p - / / / / / / /
o qualcomm sm6650_firmware - / / / / / / /
h qualcomm sm6650 - / / / / / / /
o qualcomm sm7635_firmware - / / / / / / /
h qualcomm sm7635 - / / / / / / /
o qualcomm sm7675_firmware - / / / / / / /
h qualcomm sm7675 - / / / / / / /
o qualcomm sm7675p_firmware - / / / / / / /
h qualcomm sm7675p - / / / / / / /
o qualcomm sm8550_firmware - / / / / / / /
h qualcomm sm8550 - / / / / / / /
o qualcomm sm8550p_firmware - / / / / / / /
h qualcomm sm8550p - / / / / / / /
o qualcomm sm8635_firmware - / / / / / / /
h qualcomm sm8635 - / / / / / / /
o qualcomm sm8635p_firmware - / / / / / / /
h qualcomm sm8635p - / / / / / / /
o qualcomm sm8650_firmware - / / / / / / /
h qualcomm sm8650 - / / / / / / /
o qualcomm sm8650p_firmware - / / / / / / /
h qualcomm sm8650p - / / / / / / /
o qualcomm sm8650q_firmware - / / / / / / /
h qualcomm sm8650q - / / / / / / /
o qualcomm sm8750_firmware - / / / / / / /
h qualcomm sm8750 - / / / / / / /
o qualcomm sm8750p_firmware - / / / / / / /
h qualcomm sm8750p - / / / / / / /
o qualcomm sxr2330p_firmware - / / / / / / /
h qualcomm sxr2330p - / / / / / / /
o qualcomm qca6391_firmware - / / / / / / /
h qualcomm qca6391 - / / / / / / /
o qualcomm qca6698aq_firmware - / / / / / / /
h qualcomm qca6698aq - / / / / / / /
o qualcomm qcn9011_firmware - / / / / / / /
h qualcomm qcn9011 - / / / / / / /
o qualcomm qcn9012_firmware - / / / / / / /
h qualcomm qcn9012 - / / / / / / /
o qualcomm qcn9274_firmware - / / / / / / /
h qualcomm qcn9274 - / / / / / / /
o qualcomm wcn3910_firmware - / / / / / / /
h qualcomm wcn3910 - / / / / / / /
o qualcomm wcn3950_firmware - / / / / / / /
h qualcomm wcn3950 - / / / / / / /
o qualcomm wcn6650_firmware - / / / / / / /
h qualcomm wcn6650 - / / / / / / /
o qualcomm wcn6750_firmware - / / / / / / /
h qualcomm wcn6750 - / / / / / / /
o qualcomm wcn6755_firmware - / / / / / / /
h qualcomm wcn6755 - / / / / / / /
o qualcomm wcn6855_firmware - / / / / / / /
h qualcomm wcn6855 - / / / / / / /
o qualcomm wcn6856_firmware - / / / / / / /
h qualcomm wcn6856 - / / / / / / /
o qualcomm wcn7850_firmware - / / / / / / /
h qualcomm wcn7850 - / / / / / / /
o qualcomm wcn7851_firmware - / / / / / / /
h qualcomm wcn7851 - / / / / / / /
o qualcomm wcn7860_firmware - / / / / / / /
h qualcomm wcn7860 - / / / / / / /
o qualcomm wcn7861_firmware - / / / / / / /
h qualcomm wcn7861 - / / / / / / /
o qualcomm wcn7880_firmware - / / / / / / /
h qualcomm wcn7880 - / / / / / / /
o qualcomm wcn7881_firmware - / / / / / / /
h qualcomm wcn7881 - / / / / / / /
o qualcomm qcm5430_firmware - / / / / / / /
h qualcomm qcm5430 - / / / / / / /
o qualcomm qcm6490_firmware - / / / / / / /
h qualcomm qcm6490 - / / / / / / /
o qualcomm qcm8550_firmware - / / / / / / /
h qualcomm qcm8550 - / / / / / / /
o qualcomm qcs5430_firmware - / / / / / / /
h qualcomm qcs5430 - / / / / / / /
o qualcomm qcs615_firmware - / / / / / / /
h qualcomm qcs615 - / / / / / / /

CVSS Score

7.8 / 10

CVSS Data - 3.1

  • Attack Vector: LOCAL
  • Attack Complexity: LOW
  • Privileges Required: LOW
  • Scope: UNCHANGED
  • Confidentiality Impact: HIGH
  • Integrity Impact: HIGH
  • Availability Impact: HIGH
  • CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

    View Vector String

Timeline

Published: Sept. 24, 2025, 4:15 p.m.
Last Modified: Sept. 25, 2025, 4:08 p.m.

Status : Analyzed

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

product-security@qualcomm.com

*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.