CVE-2025-21480
Last modified
CVE-2025-21480 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.. CISA has confirmed active exploitation in the wild. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Aqt1000 Firmware | All versions |
| Qualcomm | Fastconnect 6200 Firmware | All versions |
| Qualcomm | Fastconnect 6700 Firmware | All versions |
| Qualcomm | Fastconnect 6800 Firmware | All versions |
| Qualcomm | Fastconnect 6900 Firmware | All versions |
| Qualcomm | Fastconnect 7800 Firmware | All versions |
| Qualcomm | Qca6391 Firmware | All versions |
| Qualcomm | Qcm4490 Firmware | All versions |
| Qualcomm | Qcs4490 Firmware | All versions |
| Qualcomm | Sc8380xp Firmware | All versions |
| Qualcomm | Sd855 Firmware | All versions |
| Qualcomm | Sm4635 Firmware | All versions |
| Qualcomm | Sm6250 Firmware | All versions |
| Qualcomm | Sm6650 Firmware | All versions |
| Qualcomm | Sm6650p Firmware | All versions |
| Qualcomm | Sm7325p Firmware | All versions |
| Qualcomm | Sm7635 Firmware | All versions |
| Qualcomm | Sm7675 Firmware | All versions |
| Qualcomm | Sm7675p Firmware | All versions |
| Qualcomm | Sm8550p Firmware | All versions |
| Qualcomm | Sm8635 Firmware | All versions |
| Qualcomm | Sm8635p Firmware | All versions |
| Qualcomm | Sm8650q Firmware | All versions |
| Qualcomm | Snapdragon 4 Gen 1 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 460 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 480 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 480\+ 5g Mobile Platform \(Sm4350-Ac\) Firmware | All versions |
| Qualcomm | Snapdragon 662 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 680 4g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 685 4g Mobile Platform \(Sm6225-Ad\) Firmware | All versions |
| Qualcomm | Snapdragon 690 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 695 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 720g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 778g 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 778g\+ 5g Mobile Platform \(Sm7325-Ae\) Firmware | All versions |
| Qualcomm | Snapdragon 782g Mobile Platform \(Sm7325-Af\) Firmware | All versions |
| Qualcomm | Snapdragon 7c\+ Gen 3 Compute Firmware | All versions |
| Qualcomm | Snapdragon 8 Gen 2 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 8 Gen 3 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 8\+ Gen 2 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 855 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 855\+\/860 Mobile Platform \(Sm8150-Ac\) Firmware | All versions |
| Qualcomm | Snapdragon 865 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 865\+ 5g Mobile Platform \(Sm8250-Ab\) Firmware | All versions |
| Qualcomm | Snapdragon 870 5g Mobile Platform \(Sm8250-Ac\) Firmware | All versions |
| Qualcomm | Snapdragon 888 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 888\+ 5g Mobile Platform \(Sm8350-Ac\) Firmware | All versions |
| Qualcomm | Snapdragon Ar1 Gen 1 Firmware | All versions |
| Qualcomm | Snapdragon Ar1 Gen 1 Platform \"Luna1\" Firmware | All versions |
| Qualcomm | Snapdragon X55 5g Modem-Rf System Firmware | All versions |
Showing 50 of 76 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-21480?
How severe is CVE-2025-21480?
How do I fix CVE-2025-21480?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-21474Memory corruption while processing commands from A2dp sink c…7.8
- CVE-2025-21475Memory corruption while processing escape code, when Display…7.8
- CVE-2025-21476Memory corruption when passing parameters to the Trusted Vir…7.8
- CVE-2025-21477Transient DOS while processing CCCH data when NW sends data …7.5
- CVE-2025-21479Memory corruption due to unauthorized command execution in G…8.6
- CVE-2025-2148A vulnerability was found in PyTorch 2.6.0+cu124. It has bee…7.5
- CVE-2025-21481Memory corruption while performing private key encryption in…7.8
- CVE-2025-21482Cryptographic issue while performing RSA PKCS padding decodi…7.1
- CVE-2025-21483Memory corruption when the UE receives an RTP packet from th…9.8
- CVE-2025-21484Information disclosure when UE receives the RTP packet from …8.2
- CVE-2025-21485Memory corruption while processing INIT and multimode invoke…7.8
- CVE-2025-21486Memory corruption during dynamic process creation call when …7.8
Are you affected by CVE-2025-21480?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
