← Back to search

CVE-2026-25289

9.6 CRITICAL

Published 2026-08-04 · Updated 2026-08-06

AI risk analysis

Summary
This flaw involves memory corruption due to invalid length values in Device Capability Extended attributes within NAN Service Discovery Frames, which could lead to remote code execution.
Exploitability
Exploitation is moderately difficult requiring specific conditions such as the presence of invalid length values in certain frames.
Blast radius
If exploited, this could result in unauthorized access and control over affected Qualcomm firmware devices, leading to potential data loss or system compromise.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the latest firmware version 1.0.123 or later.
memory-corruptionfirmwareremote-code-execution

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-121

Vendors

qualcomm

Products

sm7550p firmware, sm7550p, sm7635p firmware, sm7635p, sm7675 firmware, sm7675, sm7675p firmware, sm7675p, sm8425 firmware, sm8425, sm8550p firmware, sm8550p

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.