{"id":"CVE-2026-25254","published":"2026-09-22T10:17:08.583","lastModified":"2026-09-25T13:37:41.860","description":"Improper authorization leads to Remote Code Execution via SocketIO interface.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-285"],"vendors":["qualcomm"],"products":["software center"],"references":[{"url":"https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2026-bulletin.html","tags":["Vendor Advisory"]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"A flaw in the SocketIO interface allows unauthorized remote code execution due to improper authorization, posing a critical risk.","exploitability":"Exploitation requires access to the SocketIO interface, which could be challenging if proper access controls are in place.","blast_radius":"If exploited, this flaw could lead to full system compromise, allowing attackers to execute arbitrary code on the affected device.","remediation":"Disable the SocketIO feature or restrict access to it to prevent unauthorized remote code execution.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","auth-bypass","socketio","remote-code-execution"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:58:59.483Z"}}