CVE-2025-27033

Sept. 25, 2025, 4:08 p.m.

6.1
Medium

Description

Information disclosure while running video usecase having rogue firmware.

Product(s) Impacted

Vendor Product Versions
Qualcomm
  • Qcm5430 Firmware
  • Qcm5430
  • Qcm6490 Firmware
  • Qcm6490
  • Qcs5430 Firmware
  • Qcs5430
  • Qcs6490 Firmware
  • Qcs6490
  • Qcm8550 Firmware
  • Qcm8550
  • Qcs8550 Firmware
  • Qcs8550
  • Qcs615 Firmware
  • Qcs615
  • Qcs9100 Firmware
  • Qcs9100
  • Sm6650 Firmware
  • Sm6650
  • Sm7635 Firmware
  • Sm7635
  • Sm8650 Firmware
  • Sm8650
  • Sm8650p Firmware
  • Sm8650p
  • Sm8650q Firmware
  • Sm8650q
  • Sm7675 Firmware
  • Sm7675
  • Sm7675p Firmware
  • Sm7675p
  • Sm8635 Firmware
  • Sm8635
  • Sm8635p Firmware
  • Sm8635p
  • Sm8750 Firmware
  • Sm8750
  • Sm8750p Firmware
  • Sm8750p
  • Sxr2330p Firmware
  • Sxr2330p
  • Wcn6750 Firmware
  • Wcn6750
  • Wcn6856 Firmware
  • Wcn6856
  • Qcn9274 Firmware
  • Qcn9274
  • Wcn7851 Firmware
  • Wcn7851
  • Qca6698aq Firmware
  • Qca6698aq
  • Wcn6650 Firmware
  • Wcn6650
  • Wcn6755 Firmware
  • Wcn6755
  • Wcn7850 Firmware
  • Wcn7850
  • Wcn7880 Firmware
  • Wcn7880
  • Wcn7860 Firmware
  • Wcn7860
  • Wcn7861 Firmware
  • Wcn7861
  • Wcn7881 Firmware
  • Wcn7881
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -
  • -

Weaknesses

Common security weaknesses mapped to this vulnerability.

CWE-126
Buffer Over-read
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

*CPE(s)

Affected systems and software identified for this CVE.

Type Vendor Product Version Update Edition Language Software Edition Target Software Target Hardware Other Information
o qualcomm qcm5430_firmware - / / / / / / /
h qualcomm qcm5430 - / / / / / / /
o qualcomm qcm6490_firmware - / / / / / / /
h qualcomm qcm6490 - / / / / / / /
o qualcomm qcs5430_firmware - / / / / / / /
h qualcomm qcs5430 - / / / / / / /
o qualcomm qcs6490_firmware - / / / / / / /
h qualcomm qcs6490 - / / / / / / /
o qualcomm qcm8550_firmware - / / / / / / /
h qualcomm qcm8550 - / / / / / / /
o qualcomm qcs8550_firmware - / / / / / / /
h qualcomm qcs8550 - / / / / / / /
o qualcomm qcs615_firmware - / / / / / / /
h qualcomm qcs615 - / / / / / / /
o qualcomm qcs9100_firmware - / / / / / / /
h qualcomm qcs9100 - / / / / / / /
o qualcomm sm6650_firmware - / / / / / / /
h qualcomm sm6650 - / / / / / / /
o qualcomm sm7635_firmware - / / / / / / /
h qualcomm sm7635 - / / / / / / /
o qualcomm sm8650_firmware - / / / / / / /
h qualcomm sm8650 - / / / / / / /
o qualcomm sm8650p_firmware - / / / / / / /
h qualcomm sm8650p - / / / / / / /
o qualcomm sm8650q_firmware - / / / / / / /
h qualcomm sm8650q - / / / / / / /
o qualcomm sm7675_firmware - / / / / / / /
h qualcomm sm7675 - / / / / / / /
o qualcomm sm7675p_firmware - / / / / / / /
h qualcomm sm7675p - / / / / / / /
o qualcomm sm8635_firmware - / / / / / / /
h qualcomm sm8635 - / / / / / / /
o qualcomm sm8635p_firmware - / / / / / / /
h qualcomm sm8635p - / / / / / / /
o qualcomm sm8750_firmware - / / / / / / /
h qualcomm sm8750 - / / / / / / /
o qualcomm sm8750p_firmware - / / / / / / /
h qualcomm sm8750p - / / / / / / /
o qualcomm sxr2330p_firmware - / / / / / / /
h qualcomm sxr2330p - / / / / / / /
o qualcomm wcn6750_firmware - / / / / / / /
h qualcomm wcn6750 - / / / / / / /
o qualcomm wcn6856_firmware - / / / / / / /
h qualcomm wcn6856 - / / / / / / /
o qualcomm qcn9274_firmware - / / / / / / /
h qualcomm qcn9274 - / / / / / / /
o qualcomm wcn7851_firmware - / / / / / / /
h qualcomm wcn7851 - / / / / / / /
o qualcomm qca6698aq_firmware - / / / / / / /
h qualcomm qca6698aq - / / / / / / /
o qualcomm wcn6650_firmware - / / / / / / /
h qualcomm wcn6650 - / / / / / / /
o qualcomm wcn6755_firmware - / / / / / / /
h qualcomm wcn6755 - / / / / / / /
o qualcomm wcn7850_firmware - / / / / / / /
h qualcomm wcn7850 - / / / / / / /
o qualcomm wcn7880_firmware - / / / / / / /
h qualcomm wcn7880 - / / / / / / /
o qualcomm wcn7860_firmware - / / / / / / /
h qualcomm wcn7860 - / / / / / / /
o qualcomm wcn7861_firmware - / / / / / / /
h qualcomm wcn7861 - / / / / / / /
o qualcomm wcn7881_firmware - / / / / / / /
h qualcomm wcn7881 - / / / / / / /

CVSS Score

6.1 / 10

CVSS Data - 3.1

  • Attack Vector: LOCAL
  • Attack Complexity: LOW
  • Privileges Required: LOW
  • Scope: UNCHANGED
  • Confidentiality Impact: HIGH
  • Integrity Impact: NONE
  • Availability Impact: LOW
  • CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

    View Vector String

Timeline

Published: Sept. 24, 2025, 4:15 p.m.
Last Modified: Sept. 25, 2025, 4:08 p.m.

Status : Analyzed

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

product-security@qualcomm.com

*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.