Buffer over-read in Qualcomm products - CVE-2025-47326
Published: September 1, 2025
Vulnerability identifier: #VU114648
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-47326
CWE-ID: CWE-126
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation in WLAN HAL. A remote attacker can perform a denial of service (DoS) attack.
Affected software
QCN6412
QMP1000
QFW7124
QFW7114
QCN9274
QCN9160
QCN9100
QCN9074
QCN9072
QCN9070
QCN9024
QCN9022
QCN9012
QCN9000
QCN6432
QCN6422
QXM8083
QCN6402
QCN6274
QCN6224
QCN6122
QCN6112
QCN6024
QCN6023
QCN5224
QCN5164
QCN5154
QCN5152
QCN5124
QCN5122
WCD9378
WSA8845H
WSA8845
WSA8840
WSA8835
WSA8830
WCN7881
WCN7880
WCN7861
WCN7860
WCN7750
WCN6755
WCN6650
WCD9395
QCN5052
WCD9340
SW-only
Snapdragon X75 5G Modem-RF System
Snapdragon X72 5G Modem-RF System
Snapdragon X65 5G Modem-RF System
SM8750P
SM8750
SM8735
SM7635P
SM7635
SM6650P
SM6650
SDX65M
IPQ5332
IPQ8173
IPQ8078A
IPQ8078
IPQ8076A
IPQ8076
IPQ8074A
IPQ8072A
IPQ8071A
IPQ8070A
IPQ6028
IPQ6018
IPQ6010
IPQ6000
IPQ5424
IPQ8174
IPQ5312
IPQ5302
IPQ5300
IPQ5028
IPQ5010
Immersive Home 326 Platform
Immersive Home 3210 Platform
Immersive Home 318 Platform
Immersive Home 316 Platform
Immersive Home 216 Platform
Immersive Home 214 Platform
FastConnect 7800
FastConnect 6900
CSR8811
QCA8102
QCN5024
QCN5022
QCF8001
QCF8000SFP
QCF8000
QCC710
QCA9889
QCA9888
QCA8386
QCA8385
QCA8384
QCA8337
QCA8112
QCA8111
AR8035
QCA8101
QCA8085
QCA8084
QCA8082
QCA8081
QCA8080
QCA8075
QCA4024
QCA0000
IPQ9574
IPQ9570
IPQ9554
IPQ9048
IPQ9008
Samsung Mobile Firmware
QCN6132
WSA8832
SDX55
Google Android
QMP1000
QFW7124
QFW7114
QCN9274
QCN9160
QCN9100
QCN9074
QCN9072
QCN9070
QCN9024
QCN9022
QCN9012
QCN9000
QCN6432
QCN6422
QXM8083
QCN6402
QCN6274
QCN6224
QCN6122
QCN6112
QCN6024
QCN6023
QCN5224
QCN5164
QCN5154
QCN5152
QCN5124
QCN5122
WCD9378
WSA8845H
WSA8845
WSA8840
WSA8835
WSA8830
WCN7881
WCN7880
WCN7861
WCN7860
WCN7750
WCN6755
WCN6650
WCD9395
QCN5052
WCD9340
SW-only
Snapdragon X75 5G Modem-RF System
Snapdragon X72 5G Modem-RF System
Snapdragon X65 5G Modem-RF System
SM8750P
SM8750
SM8735
SM7635P
SM7635
SM6650P
SM6650
SDX65M
IPQ5332
IPQ8173
IPQ8078A
IPQ8078
IPQ8076A
IPQ8076
IPQ8074A
IPQ8072A
IPQ8071A
IPQ8070A
IPQ6028
IPQ6018
IPQ6010
IPQ6000
IPQ5424
IPQ8174
IPQ5312
IPQ5302
IPQ5300
IPQ5028
IPQ5010
Immersive Home 326 Platform
Immersive Home 3210 Platform
Immersive Home 318 Platform
Immersive Home 316 Platform
Immersive Home 216 Platform
Immersive Home 214 Platform
FastConnect 7800
FastConnect 6900
CSR8811
QCA8102
QCN5024
QCN5022
QCF8001
QCF8000SFP
QCF8000
QCC710
QCA9889
QCA9888
QCA8386
QCA8385
QCA8384
QCA8337
QCA8112
QCA8111
AR8035
QCA8101
QCA8085
QCA8084
QCA8082
QCA8081
QCA8080
QCA8075
QCA4024
QCA0000
IPQ9574
IPQ9570
IPQ9554
IPQ9048
IPQ9008
Samsung Mobile Firmware
QCN6132
WSA8832
SDX55
Google Android
How to mitigate CVE-2025-47326
Install security update from vendor's website.
Samsung Mobile Firmware - update to SMR-SEP-2025
Google Android - addressed in versions 13 2025-09-05, 14 2025-09-05, 15 2025-09-05, 16 2025-09-05
Google Android - addressed in versions 13 2025-09-05, 14 2025-09-05, 15 2025-09-05, 16 2025-09-05