← Back to search

CVE-2026-24077

6.5 MEDIUM

Published 2026-08-04 · Updated 2026-08-06

AI risk analysis

Summary
The flaw involves improper handling of length fields during wireless network channel switch processing, leading to potential information disclosure.
Exploitability
Exploitation requires specific conditions and is moderately difficult; attackers need access to improperly formatted length fields.
Blast radius
If exploited, it could lead to sensitive information exposure within the affected firmware's environment.
Prioritized remediation
Update to the latest firmware versions for all affected devices immediately.
info-discwirelessfirmware

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-191

Vendors

qualcomm

Products

aqt1000 firmware, aqt1000, ar8035 firmware, ar8035, csra6620 firmware, csra6620, csra6640 firmware, csra6640, fastconnect 6200 firmware, fastconnect 6200, wcd9395 firmware, wcd9395

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.