CVE-2026-24078
6.5 MEDIUMPublished 2026-08-04 · Updated 2026-08-06
AI risk analysis
- Summary
- The flaw allows information disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling, potentially exposing sensitive data.
- Exploitability
- Exploitation requires specific conditions such as failed IPSec negotiation and involves NG-eCall SIP signaling; it may be moderately difficult to exploit.
- Blast radius
- If exploited, the impact could be significant in terms of data exposure within affected Qualcomm 5G fixed wireless access platforms.
- Prioritized remediation
- Update firmware to the latest version to address the vulnerability.
info-disc5gfirmwarequalcomm
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-359
Vendors
qualcomm
Products
5g fixed wireless access platform firmware, 5g fixed wireless access platform, ar8035 firmware, ar8035, csra6620 firmware, csra6620, csra6640 firmware, csra6640, fastconnect 6200 firmware, fastconnect 6200, qcs4490 firmware, qcs4490
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.