CVE-2025-21484
HIGHCVSS 8.2/10EPSS 0.24%
Last modified
CVE-2025-21484 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Sm8750 Firmware | All versions |
| Qualcomm | Sm8750p Firmware | All versions |
| Qualcomm | Sm8850 Firmware | All versions |
| Qualcomm | Sm8850p Firmware | All versions |
| Qualcomm | Smart Audio 200 Platform Firmware | All versions |
| Qualcomm | Smart Display 200 Platform Firmware | All versions |
| Qualcomm | Snapdragon 208 Processor Firmware | All versions |
| Qualcomm | Snapdragon 210 Processor Firmware | All versions |
| Qualcomm | Snapdragon 212 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 4 Gen 1 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 429 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 460 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 480 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 480\+ 5g Mobile Platform \(Sm4350-Ac\) Firmware | All versions |
| Qualcomm | Snapdragon 625 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 626 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 660 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 662 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 675 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 678 Mobile Platform \(Sm6150-Ac\) Firmware | All versions |
| Qualcomm | Snapdragon 680 4g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 685 4g Mobile Platform \(Sm6225-Ad\) Firmware | All versions |
| Qualcomm | Snapdragon 690 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 695 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 720g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 730 Mobile Platform \(Sm7150-Aa\) Firmware | All versions |
| Qualcomm | Snapdragon 730g Mobile Platform \(Sm7150-Ab\) Firmware | All versions |
| Qualcomm | Snapdragon 732g Mobile Platform \(Sm7150-Ac\) Firmware | All versions |
| Qualcomm | Snapdragon 750g 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 765 5g Mobile Platform \(Sm7250-Aa\) Firmware | All versions |
| Qualcomm | Snapdragon 765g 5g Mobile Platform \(Sm7250-Ab\) Firmware | All versions |
| Qualcomm | Snapdragon 768g 5g Mobile Platform \(Sm7250-Ac\) Firmware | All versions |
| Qualcomm | Snapdragon 8 Gen 3 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 8\+ Gen 1 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 820 Automotive Platform Firmware | All versions |
| Qualcomm | Snapdragon 835 Mobile Pc Platform Firmware | All versions |
| Qualcomm | Snapdragon 845 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 855 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 855\+\/860 Mobile Platform \(Sm8150-Ac\) Firmware | All versions |
| Qualcomm | Snapdragon 865 5g Mobile Platform Firmware | All versions |
| Qualcomm | Apq8064au Firmware | All versions |
| Qualcomm | Aqt1000 Firmware | All versions |
| Qualcomm | Fastconnect 6200 Firmware | All versions |
| Qualcomm | Fastconnect 6700 Firmware | All versions |
| Qualcomm | Fastconnect 6800 Firmware | All versions |
| Qualcomm | Fastconnect 6900 Firmware | All versions |
| Qualcomm | Fastconnect 7800 Firmware | All versions |
| Qualcomm | Msm8108 Firmware | All versions |
| Qualcomm | Msm8209 Firmware | All versions |
| Qualcomm | Msm8608 Firmware | All versions |
Showing 50 of 173 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-21484?
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
How severe is CVE-2025-21484?
CVE-2025-21484 has a CVSS score of 8.2/10 (HIGH severity). The EPSS model estimates a 0.24% probability of exploitation in the next 30 days.
How do I fix CVE-2025-21484?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-21479Memory corruption due to unauthorized command execution in G…8.6
- CVE-2025-2148A vulnerability was found in PyTorch 2.6.0+cu124. It has bee…7.5
- CVE-2025-21480Memory corruption due to unauthorized command execution in G…8.6
- CVE-2025-21481Memory corruption while performing private key encryption in…7.8
- CVE-2025-21482Cryptographic issue while performing RSA PKCS padding decodi…7.1
- CVE-2025-21483Memory corruption when the UE receives an RTP packet from th…9.8
- CVE-2025-21485Memory corruption while processing INIT and multimode invoke…7.8
- CVE-2025-21486Memory corruption during dynamic process creation call when …7.8
- CVE-2025-21487Information disclosure while decoding RTP packet received by…8.2
- CVE-2025-21488Information disclosure while decoding this RTP packet header…8.2
- CVE-2025-21489Vulnerability in the Oracle Advanced Outbound Telephony prod…6.1
- CVE-2025-2149A vulnerability was found in PyTorch 2.6.0+cu124. It has bee…2.5
Are you affected by CVE-2025-21484?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
