CVE-2025-21427
HIGHCVSS 8.2/10EPSS 0.20%
Last modified
CVE-2025-21427 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Sm6250 Firmware | All versions |
| Qualcomm | Sm6370 Firmware | All versions |
| Qualcomm | Sm7315 Firmware | All versions |
| Qualcomm | Sm7325p Firmware | All versions |
| Qualcomm | Sm8550p Firmware | All versions |
| Qualcomm | Smart Display 200 Platform Firmware | All versions |
| Qualcomm | Snapdragon 210 Firmware | All versions |
| Qualcomm | Snapdragon 212 Mobile Firmware | All versions |
| Qualcomm | Snapdragon 4 Gen 1 Mobile Firmware | All versions |
| Qualcomm | Snapdragon 4 Gen 2 Mobile Firmware | All versions |
| Qualcomm | Snapdragon 429 Mobile Firmware | All versions |
| Qualcomm | Snapdragon 460 Mobile Firmware | All versions |
| Qualcomm | Snapdragon 480 5g Mobile Firmware | All versions |
| Qualcomm | Snapdragon 480\+ 5g Mobile Firmware | All versions |
| Qualcomm | Snapdragon 625 Mobile Firmware | All versions |
| Qualcomm | Snapdragon 626 Mobile Firmware | All versions |
| Qualcomm | Snapdragon 660 Mobile Firmware | All versions |
| Qualcomm | Snapdragon 662 Mobile Firmware | All versions |
| Qualcomm | Snapdragon 670 Mobile Firmware | All versions |
| Qualcomm | Snapdragon 675 Mobile Firmware | All versions |
| Qualcomm | Snapdragon 678 Mobile Firmware | All versions |
| Qualcomm | Snapdragon 680 4g Mobile Firmware | All versions |
| Qualcomm | Snapdragon 685 4g Mobile Firmware | All versions |
| Qualcomm | Snapdragon 695 5g Mobile Firmware | All versions |
| Qualcomm | Snapdragon 710 Mobile Firmware | All versions |
| Qualcomm | Snapdragon 720g Mobile Firmware | All versions |
| Qualcomm | Snapdragon 730 Mobile Firmware | All versions |
| Qualcomm | Snapdragon 730g Mobile Firmware | All versions |
| Qualcomm | Snapdragon 732g Mobile Firmware | All versions |
| Qualcomm | Snapdragon 778g 5g Mobile Firmware | All versions |
| Qualcomm | Snapdragon 778g\+ 5g Mobile Firmware | All versions |
| Qualcomm | Snapdragon 780g 5g Mobile Firmware | All versions |
| Qualcomm | Snapdragon 782g Mobile Firmware | All versions |
| Qualcomm | Snapdragon 7c\+ Gen 3 Compute Firmware | All versions |
| Qualcomm | Snapdragon 8 Gen 1 Mobile Firmware | All versions |
| Qualcomm | Snapdragon 8 Gen 2 Mobile Firmware | All versions |
| Qualcomm | Snapdragon 8 Gen 3 Mobile Firmware | All versions |
| Qualcomm | Snapdragon 8\+ Gen 1 Mobile Firmware | All versions |
| Qualcomm | Snapdragon 8\+ Gen 2 Mobile Firmware | All versions |
| Qualcomm | Snapdragon 820 Automotive Firmware | All versions |
| Qualcomm | Apq8064au Firmware | All versions |
| Qualcomm | Aqt1000 Firmware | All versions |
| Qualcomm | Fastconnect 6200 Firmware | All versions |
| Qualcomm | Fastconnect 6700 Firmware | All versions |
| Qualcomm | Fastconnect 6800 Firmware | All versions |
| Qualcomm | Fastconnect 6900 Firmware | All versions |
| Qualcomm | Fastconnect 7800 Firmware | All versions |
| Qualcomm | Msm8996au Firmware | All versions |
| Qualcomm | Qam8255p Firmware | All versions |
| Qualcomm | Qam8295p Firmware | All versions |
Showing 50 of 179 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-21427?
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
How severe is CVE-2025-21427?
CVE-2025-21427 has a CVSS score of 8.2/10 (HIGH severity). The EPSS model estimates a 0.20% probability of exploitation in the next 30 days.
How do I fix CVE-2025-21427?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-21421Memory corruption while processing escape code in API.7.8
- CVE-2025-21422Cryptographic issue while processing crypto API calls, missi…7.8
- CVE-2025-21423Memory corruption occurs when handling client calls to Enabl…7.8
- CVE-2025-21424Memory corruption while calling the NPU driver APIs concurre…7.8
- CVE-2025-21425Memory corruption may occur due top improper access control …7.8
- CVE-2025-21426Memory corruption while processing camera TPG write request.7.8
- CVE-2025-21428Memory corruption occurs while connecting a STA to an AP and…7.5
- CVE-2025-21429Memory corruption occurs while connecting a STA to an AP and…7.5
- CVE-2025-21430Transient DOS while connecting STA to AP and initiating ADD …7.5
- CVE-2025-21431Information disclosure may be there when a guest VM is conne…4.7
- CVE-2025-21432Memory corruption while retrieving the CBOR data from TA.7.8
- CVE-2025-21433Transient DOS when importing a PKCS#8-encoded RSA private ke…5.5
Are you affected by CVE-2025-21427?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
