CVE-2026-25275High· 7.5▾ TwilightTransient DOS when processing authentication frames with invalid FILS information element header lengths.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
q-7790_firmwareqam8255p_firmwareqam8295p_firmwareqamsrv1h_firmwareqamsrv1m_firmwareqca0000_firmwareqca2062_firmwareqca2064_firmwareqca2065_firmwareqca2066_firmwareqca4024_firmwareqca6391_firmwareqca6420_firmwareqca6428_firmwareqca6430_firmwareqca6438_firmwareqca6554a_firmwareqca6564au_firmwareqca6574_firmwareqca6574a_firmwareqca6574au_firmwareqca6584au_firmwareqca6595_firmwareqca6595au_firmwareqca6678aq_firmwareqca6688aq_firmwareqca6696_firmwareqca6698aq_firmwareqca6698au_firmwareqca6777aq_firmwareqca6787aq_firmwareqca6797aq_firmwareqca8072_firmwareqca8075_firmwareqca8080_firmwareqca8081_firmwareqca8082_firmwareqca8084_firmwareqca8085_firmwareqca8337_firmwaresm7550_firmwaresm7550p_firmwaresm7635p_firmwaresm7675_firmwaresm7675p_firmwaresm7750p_firmwaresm8475p_firmwaresm8550p_firmwaresm8635_firmwaresm8635p_firmwaresm8650q_firmwaresm8735p_firmwaresm8750p_firmwaresm8845p_firmwaresm8950_firmwaresm8950p_firmwaresm8975_firmwaresm8975p_firmwaresmart_audio_400_platform_firmwaresnapdragon_4_gen_1_mobile_platform_firmwaresnapdragon_4_gen_2_mobile_platform_firmwaresnapdragon_460_mobile_platform_firmwaresnapdragon_480_5g_mobile_platform_firmwaresnapdragon_480+_5g_mobile_platform_firmwaresnapdragon_6_gen_1_mobile_platform_firmwaresnapdragon_6_gen_3_mobile_platform_firmwaresnapdragon_6_gen_4_mobile_platform_firmwaresnapdragon_660_mobile_platform_firmwaresnapdragon_662_mobile_platform_firmwaresnapdragon_680_4g_mobile_platform_firmwaresnapdragon_685_4g_mobile_platform_firmwaresnapdragon_690_5g_mobile_platform_firmwaresnapdragon_695_5g_mobile_platform_firmwaresnapdragon_7_gen_1_mobile_platform_firmwaresnapdragon_7_gen_4_mobile_platform_firmwaresnapdragon_7+_gen_2_mobile_platform_firmwaresnapdragon_778g_5g_mobile_platform_firmwaresnapdragon_778g+_5g_mobile_platform_firmwaresnapdragon_782g_mobile_platform_firmwaresnapdragon_7c_compute_platform_firmwaresnapdragon_g1_gen_2_gaming_platform_firmware5g_fixed_wireless_access_platform_firmwareaqt1000_firmwarear8031_firmwarear8035_firmwarec110100_firmwarecologne_firmwarecongo_firmwarecq2390m_firmwarecq2390s_firmwarecq7790_firmwarecq7790m_firmwarecq8725s_firmwarecq8750m_firmwarecq8845s_firmwarecsr8811_firmwarecsra6620_firmwarecsra6640_firmwarecsrb31024_firmwarefastconnect_6200_firmwareRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-24081High· 7.4Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
CVE-2026-24075High· 7.8Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.
CVE-2026-25284High· 7.3Information Disclosure when a pointer is reused after being deallocated.
CVE-2026-25294High· 7.4Transient DOS while parsing frame during channel usage.
CVE-2026-24073High· 7.8Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.
CVE-2026-24074High· 7.8Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.