CVE-2025-47401Medium· 6.5▾ SunlitTransient DOS when processing target power rate tables during channel configuration.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Transient DOS when processing target power rate tables during channel configuration.
fastconnect_6200_firmwarefastconnect_6700_firmwarefastconnect_6900_firmwarefastconnect_7800_firmwareflight_rb5_5g_firmwarefwa_gen_3_ultra_firmwareg2_gen_1_firmwareg3x_gen_2_firmwareimmersive_home_3210_firmwareimmersive_home_326_firmwareipq5300_firmwareipq5302_firmwareipq5312_firmwareipq5332_firmwareipq9008_firmwareipq9554_firmwareipq9570_firmwareipq9574_firmwareiqx5121_firmwareiqx7181_firmwarelemans_au_lgit_firmwarelemansau_firmwaremarina_firmwaremilos_firmwaremilos_iot_firmwaremolokai_firmwaremonaco_iot_firmwarenetrani_firmwarenetworking_pro_1200_firmwarenetworking_pro_1210_firmwarenetworking_pro_1610_firmwarenetworking_pro_610_firmwarenetworking_pro_810_firmwareorne_firmwarepalawan25_firmwarepandeiro_firmwareqam8255p_firmwareqam8295p_firmwareqam8397p_firmwareqamsrv1h_firmwaresm8650q_firmwaresm8735p_firmwaresm8750p_firmwaresm8845p_firmwaresnapdragon_4_gen_2_mobile_firmwaresnapdragon_6_gen_1_mobile_firmwaresnapdragon_6_gen_3_mobile_firmwaresnapdragon_6_gen_4_mobile_firmwaresnapdragon_7_gen_1_mobile_firmwaresnapdragon_7_gen_4_mobile_firmwaresnapdragon_7+_gen_2_mobile_firmwaresnapdragon_7s_gen_3_mobile_firmwaresnapdragon_8_elite_firmwaresnapdragon_8_elite_gen_5_firmwaresnapdragon_8_gen_1_mobile_firmwaresnapdragon_8_gen_2_mobile_firmwaresnapdragon_8_gen_3_mobile_firmwaresnapdragon_8+_gen_1_mobile_firmwaresnapdragon_8+_gen_2_mobile_firmwaresnapdragon_888_5g_mobile_firmwaresnapdragon_888+_5g_mobile_firmwaresnapdragon_8cx_gen_3_compute_firmwaresnapdragon_ar1_gen_1_firmwaresnapdragon_ar1+_gen_1_firmwaresnapdragon_auto_5g_modem-rf_firmwaresnapdragon_auto_5g_modem-rf_gen_2_firmwaresnapdragon_x32_5g_modem-rf_firmwaresnapdragon_x35_5g_modem-rf_firmwaresnapdragon_x62_5g_modem-rf_firmwaresnapdragon_x65_5g_modem-rf_firmwaresnapdragon_x72_5g_modem-rf_firmwaresnapdragon_x75_5g_modem-rf_firmwaresrv1h_firmwaresrv1m_firmwaresxr2230p_firmwaresxr2250p_firmwaresxr2330p_firmwaresxr2350p_firmwarewcd9340_firmwarewcd9370_firmwarear8035_firmwarecologne_firmwarecq7790_firmwarecq8725s_firmwarecq8750m_firmwareqamsrv1m_firmwareqca0000_firmwareqca2062_firmwareqca2064_firmwareqca2065_firmwareqca2066_firmwareqca6174a_firmwareqca6391_firmwareqca6554a_firmwareqca6564au_firmwareqca6574_firmwareqca6574a_firmwareqca6574au_firmwareqca6584au_firmwareqca6595_firmwareRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-47406Medium· 6.1Information Disclosure while processing IOCTL handler callbacks without verifying buffer size.
CVE-2025-47403Medium· 6.5Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
CVE-2025-47408High· 7.8Memory corruption when another driver calls an IOCTL with invalid input/output buffer.
CVE-2025-21488High· 8.2Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.
CVE-2025-47407High· 7.8Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level.
CVE-2025-47405High· 7.8Memory corruption when processing camera sensor input/output control codes with invalid output buffers.