CVE-2025-3461

CRITICALCVSS 9.8/10EPSS 0.50%

Last modified

CVE-2025-3461 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The Quantenna Wi-Fi chips ship with an unauthenticated telnet interface by default. This is an instance of CWE-306, "Missing Authentication for Critical Function," and is estimated as a CVSS 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This issue affects Quantenna Wi-Fi chipset through version 8.0.0.28 of the latest SDK, and appears to be unpatched at the time of this CVE record's first publishing, though the vendor has released a best practices guide for implementors of this chipset.. EPSS estimates a 0.50% chance of exploitation in the next 30 days.

Description

The Quantenna Wi-Fi chips ship with an unauthenticated telnet interface by default. This is an instance of CWE-306, "Missing Authentication for Critical Function," and is estimated as a CVSS 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This issue affects Quantenna Wi-Fi chipset through version 8.0.0.28 of the latest SDK, and appears to be unpatched at the time of this CVE record's first publishing, though the vendor has released a best practices guide for implementors of this chipset.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.50%

39.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
OnsemiQhs710 FirmwareAll versions
OnsemiQsr10ga FirmwareAll versions
OnsemiQsr10gu FirmwareAll versions
OnsemiQv840 FirmwareAll versions
OnsemiQv840c FirmwareAll versions
OnsemiQv860 FirmwareAll versions
OnsemiQv940 FirmwareAll versions
OnsemiQv942c FirmwareAll versions
OnsemiQv952c FirmwareAll versions
OnsemiQcs-Ax2-S5 FirmwareAll versions
OnsemiQcs-Ax3-A12 FirmwareAll versions
OnsemiQcs-Ax3-T12 FirmwareAll versions
OnsemiQcs-Ax3-T8 FirmwareAll versions
OnsemiQcs-Ax3-S5 FirmwareAll versions
OnsemiQcs-Ax2-A12 FirmwareAll versions
OnsemiQcs-Ax2-T12 FirmwareAll versions
OnsemiQcs-Ax2-T8 FirmwareAll versions
OnsemiQd840 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2025-3461?
The Quantenna Wi-Fi chips ship with an unauthenticated telnet interface by default. This is an instance of CWE-306, "Missing Authentication for Critical Function," and is estimated as a CVSS 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This issue affects Quantenna Wi-Fi chipset through version 8.0.0.28 of the latest SDK, and appears to be unpatched at the time of this CVE record's first publishing, though the vendor has released a best practices guide for implementors of this chipset.
How severe is CVE-2025-3461?
CVE-2025-3461 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 0.50% probability of exploitation in the next 30 days.
How do I fix CVE-2025-3461?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2025-3461?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST