CVE-2025-21487
HIGHCVSS 8.2/10EPSS 0.24%
Last modified
CVE-2025-21487 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Apq8017 Firmware | All versions |
| Qualcomm | Apq8064au Firmware | All versions |
| Qualcomm | Aqt1000 Firmware | All versions |
| Qualcomm | Fastconnect 6200 Firmware | All versions |
| Qualcomm | Fastconnect 6700 Firmware | All versions |
| Qualcomm | Snapdragon 460 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 480 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 480\+ 5g Mobile Platform \(Sm4350-Ac\) Firmware | All versions |
| Qualcomm | Snapdragon 625 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 626 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 630 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 632 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 636 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 660 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 662 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 670 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 675 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 678 Mobile Platform \(Sm6150-Ac\) Firmware | All versions |
| Qualcomm | Snapdragon 680 4g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 685 4g Mobile Platform \(Sm6225-Ad\) Firmware | All versions |
| Qualcomm | Snapdragon 690 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 695 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 710 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 720g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 730 Mobile Platform \(Sm7150-Aa\) Firmware | All versions |
| Qualcomm | Snapdragon 730g Mobile Platform \(Sm7150-Ab\) Firmware | All versions |
| Qualcomm | Snapdragon 732g Mobile Platform \(Sm7150-Ac\) Firmware | All versions |
| Qualcomm | Snapdragon 750g 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 765 5g Mobile Platform \(Sm7250-Aa\) Firmware | All versions |
| Qualcomm | Snapdragon 765g 5g Mobile Platform \(Sm7250-Ab\) Firmware | All versions |
| Qualcomm | Snapdragon 768g 5g Mobile Platform \(Sm7250-Ac\) Firmware | All versions |
| Qualcomm | Snapdragon 778g 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 778g\+ 5g Mobile Platform \(Sm7325-Ae\) Firmware | All versions |
| Qualcomm | Snapdragon 780g 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 782g Mobile Platform \(Sm7325-Af\) Firmware | All versions |
| Qualcomm | Snapdragon 7c\+ Gen 3 Compute Firmware | All versions |
| Qualcomm | Snapdragon 8 Gen 1 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 8 Gen 2 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 8 Gen 3 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 8\+ Gen 1 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 8\+ Gen 2 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 820 Automotive Platform Firmware | All versions |
| Qualcomm | Snapdragon 835 Mobile Pc Platform Firmware | All versions |
| Qualcomm | Snapdragon 845 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 855 Mobile Platform Firmware | All versions |
| Qualcomm | Fastconnect 6800 Firmware | All versions |
| Qualcomm | Fastconnect 6900 Firmware | All versions |
| Qualcomm | Fastconnect 7800 Firmware | All versions |
| Qualcomm | Msm8996au Firmware | All versions |
| Qualcomm | Qam8255p Firmware | All versions |
Showing 50 of 227 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-21487?
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
How severe is CVE-2025-21487?
CVE-2025-21487 has a CVSS score of 8.2/10 (HIGH severity). The EPSS model estimates a 0.24% probability of exploitation in the next 30 days.
How do I fix CVE-2025-21487?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Are you affected by CVE-2025-21487?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
