{"id":"CVE-2026-25289","published":"2026-08-04T16:16:24.890","lastModified":"2026-08-06T18:35:29.443","description":"Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.","cvssScore":9.6,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-121"],"vendors":["qualcomm"],"products":["sm7550p firmware","sm7550p","sm7635p firmware","sm7635p","sm7675 firmware","sm7675","sm7675p firmware","sm7675p","sm8425 firmware","sm8425","sm8550p firmware","sm8550p"],"references":[{"url":"https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html","tags":["Vendor Advisory"]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw involves memory corruption when processing Device Capability Extended attributes in specific NAN Service Discovery Frames with invalid length values, potentially leading to remote code execution.","exploitability":"Exploitation requires precise manipulation of frame lengths and is moderately difficult due to the need for detailed knowledge of the protocol and valid frame structures.","blast_radius":"If exploited, this vulnerability could lead to widespread device compromise across affected Qualcomm firmware versions, impacting a broad range of devices.","remediation":"Update all affected Qualcomm firmware to the latest version immediately to mitigate the risk.","tags":["memory-corruption","remote-code-execution","firmware-update"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:43:52.736Z"}}