{"id":"CVE-2026-25292","published":"2026-08-04T16:16:25.183","lastModified":"2026-08-06T18:35:21.163","description":"Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.","cvssScore":7.6,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-1286"],"vendors":["qualcomm"],"products":["sm6225p firmware","sm6225p","sm6450p firmware","sm6450p","sm6475p firmware","sm6475p","sm6475q firmware","sm6475q","sm6850 firmware","sm6850","sm7435 firmware","sm7435"],"references":[{"url":"https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html","tags":["Patch","Vendor Advisory"]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw involves memory corruption due to improper handling of untrusted user input in the fastboot command handler for audio framework configuration, which can lead to arbitrary code execution.","exploitability":"Exploitation requires access to the device via fastboot and manipulation of audio framework configuration commands; technical expertise is needed.","blast_radius":"If exploited, this could allow an attacker to gain full control over affected Qualcomm devices, leading to severe security implications.","remediation":"Update firmware to the latest version available from the manufacturer to patch the vulnerability.","tags":["rce","firmware","memory-corruption"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:53:24.215Z"}}