CVE-2025-21428

HIGHCVSS 7.5/10EPSS 0.21%

Last modified

CVE-2025-21428 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.

Description

Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
0.21%

10.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
QualcommSnapdragon 439 Mobile Platform FirmwareAll versions
QualcommSnapdragon 625 Mobile Platform FirmwareAll versions
QualcommSnapdragon 626 Mobile Platform FirmwareAll versions
QualcommSnapdragon 632 Mobile Platform FirmwareAll versions
QualcommSnapdragon 820 Automotive Platform FirmwareAll versions
QualcommSnapdragon Auto 5g Modem-Rf FirmwareAll versions
QualcommSnapdragon X12 Lte Modem FirmwareAll versions
QualcommSnapdragon X35 5g Modem-Rf System FirmwareAll versions
QualcommSnapdragon X5 Lte Modem FirmwareAll versions
QualcommVision Intelligence 100 Platform \(Apq8053-Aa\) FirmwareAll versions
QualcommVision Intelligence 200 Platform \(Apq8053-Ac\) FirmwareAll versions
QualcommWcd9326 FirmwareAll versions
QualcommWcd9330 FirmwareAll versions
QualcommWcd9335 FirmwareAll versions
QualcommWcd9340 FirmwareAll versions
QualcommWcn3610 FirmwareAll versions
QualcommWcn3615 FirmwareAll versions
QualcommWcn3620 FirmwareAll versions
QualcommWcn3660b FirmwareAll versions
QualcommWcn3680 FirmwareAll versions
QualcommWcn3680b FirmwareAll versions
QualcommWcn3980 FirmwareAll versions
QualcommWsa8810 FirmwareAll versions
QualcommWsa8815 FirmwareAll versions
Qualcomm9206 Lte Modem FirmwareAll versions
QualcommApq8017 FirmwareAll versions
QualcommAr8031 FirmwareAll versions
QualcommC-V2x 9150 FirmwareAll versions
QualcommCsra6620 FirmwareAll versions
QualcommCsra6640 FirmwareAll versions
QualcommFastconnect 6200 FirmwareAll versions
QualcommFastconnect 6900 FirmwareAll versions
QualcommMdm9250 FirmwareAll versions
QualcommMdm9628 FirmwareAll versions
QualcommMdm9640 FirmwareAll versions
QualcommMdm9650 FirmwareAll versions
QualcommMsm8996au FirmwareAll versions
QualcommQca6174 FirmwareAll versions
QualcommQca6174a FirmwareAll versions
QualcommQca6175a FirmwareAll versions
QualcommQca6554a FirmwareAll versions
QualcommQca6564a FirmwareAll versions
QualcommQca6564au FirmwareAll versions
QualcommQca6574 FirmwareAll versions
QualcommQca6574a FirmwareAll versions
QualcommQca6574au FirmwareAll versions
QualcommQca6584 FirmwareAll versions
QualcommQca6584au FirmwareAll versions
QualcommQca6595 FirmwareAll versions
QualcommQca6595au FirmwareAll versions

Showing 50 of 69 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2025-21428?
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.
How severe is CVE-2025-21428?
CVE-2025-21428 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 0.21% probability of exploitation in the next 30 days.
How do I fix CVE-2025-21428?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2025-21428?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST