#VU112356 Improper Authentication in Qualcomm products - CVE-2025-21450

 

#VU112356 Improper Authentication in Qualcomm products - CVE-2025-21450

Published: July 7, 2025


Vulnerability identifier: #VU112356
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2025-21450
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
AR8035
FastConnect 6200
FastConnect 6700
FastConnect 6900
FastConnect 7800
QCA6391
QCA6574A
QCA6584AU
QCA6595AU
QCA6678AQ
QCA6688AQ
QCA6696
QCA6698AQ
QCA6698AU
QCA6797AQ
QCA8081
QCA8337
QCC710
QCM4490
QCM5430
QCM6490
QCM8550
QCN6024
QCN6224
QCN6274
QCN9011
QCN9012
QCN9024
QCS4490
QCS5430
QCS6490
QCS8550
QEP8111
QFW7114
QFW7124
Qualcomm Video Collaboration VC3 Platform
SD 8 Gen1 5G
SDX61
SDX80M
SG8275P
SM4635
SM6370
SM6650
SM6650P
SM7325P
SM7635
SM7635P
SM7675
SM7675P
SM8635
SM8635P
SM8650Q
SM8750
SM8750P
Snapdragon 4 Gen 1 Mobile Platform
Snapdragon 480 5G Mobile Platform
Snapdragon 480+ 5G Mobile Platform (SM4350-AC)
Snapdragon 695 5G Mobile Platform
Snapdragon 778G 5G Mobile Platform
Snapdragon 778G+ 5G Mobile Platform (SM7325-AE)
Snapdragon 782G Mobile Platform (SM7325-AF)
Snapdragon 7c+ Gen 3 Compute
Snapdragon 8 Gen 1 Mobile Platform
Snapdragon 8 Gen 3 Mobile Platform
Snapdragon 8+ Gen 1 Mobile Platform
Snapdragon 888 5G Mobile Platform
Snapdragon 888+ 5G Mobile Platform (SM8350-AC)
Snapdragon Auto 5G Modem-RF
Snapdragon Auto 5G Modem-RF Gen 2
Snapdragon W5+ Gen 1 Wearable Platform
Snapdragon X32 5G Modem-RF System
Snapdragon X35 5G Modem-RF System
Snapdragon X62 5G Modem-RF System
Snapdragon X65 5G Modem-RF System
Snapdragon X72 5G Modem-RF System
Snapdragon X75 5G Modem-RF System
SW5100
SW5100P
WCD9340
WCD9360
WCD9370
WCD9375
WCD9378
WCD9380
WCD9385
WCD9390
WCD9395
WCN3950
WCN3980
WCN3988
WCN6450
WCN6650
WCN6755
WCN7860
WCN7861
WCN7880
WCN7881
WSA8810
WSA8815
WSA8830
WSA8835
WSA8840
WSA8845
WSA8845H
QCA6174A
QCA6574AU
SDX55
WSA8832
Software vendor:
Qualcomm

Description

The vulnerability allows a remote attacker to read and manipulate data.

The vulnerability exists due to improper input validation in GPS_GNSS. A remote attacker can read and manipulate data.


Remediation

Install security update from vendor's website.

External links