{"id":"CVE-2026-24078","published":"2026-08-04T16:16:23.237","lastModified":"2026-08-06T18:33:12.097","description":"Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.","cvssScore":6.5,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwes":["CWE-359"],"vendors":["qualcomm"],"products":["5g fixed wireless access platform firmware","5g fixed wireless access platform","ar8035 firmware","ar8035","csra6620 firmware","csra6620","csra6640 firmware","csra6640","fastconnect 6200 firmware","fastconnect 6200","qcs4490 firmware","qcs4490"],"references":[{"url":"https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html","tags":["Vendor Advisory"]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows information disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling, potentially exposing sensitive data.","exploitability":"Exploitation requires specific conditions such as failed IPSec negotiation and involves NG-eCall SIP signaling; it may be moderately difficult to exploit.","blast_radius":"If exploited, the impact could be significant in terms of data exposure within affected Qualcomm 5G fixed wireless access platforms.","remediation":"Update firmware to the latest version to address the vulnerability.","tags":["info-disc","5g","firmware","qualcomm"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T07:05:50.324Z"}}