Improper Validation of Array Index in Qualcomm products - CVE-2025-21447
Published: April 7, 2025
Vulnerability identifier: #VU107104
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-21447
CWE-ID: CWE-129
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to execute arbitrary code.
The vulnerability exists due to improper input validation in Computer Vision. A local application can execute arbitrary code.
Affected software
FastConnect 6900
FastConnect 7800
SC8380XP
WCD9380
WCD9385
WSA8840
WSA8845
WSA8845H
XPS 13 9345
Inspiron 14 5441
Inspiron 14 7441
Latitude 5455
Latitude 7455
Qualcomm FastConnect 7800 Wi-Fi and Bluetooth Driver
Qualcomm MIPI Camera Driver
FastConnect 7800
SC8380XP
WCD9380
WCD9385
WSA8840
WSA8845
WSA8845H
XPS 13 9345
Inspiron 14 5441
Inspiron 14 7441
Latitude 5455
Latitude 7455
Qualcomm FastConnect 7800 Wi-Fi and Bluetooth Driver
Qualcomm MIPI Camera Driver
How to mitigate CVE-2025-21447
Install security update from vendor's website.
Qualcomm FastConnect 7800 Wi-Fi and Bluetooth Driver - update to 1.0.4260.6000
Qualcomm MIPI Camera Driver - update to 1.1.0.54
Qualcomm MIPI Camera Driver - update to 1.1.0.54