← Back to search

CVE-2026-24078

6.5 MEDIUM

Published 2026-08-04 · Updated 2026-08-06

AI risk analysis

Summary
The flaw allows information disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling, potentially exposing sensitive data.
Exploitability
Exploitation requires specific conditions such as failed IPSec negotiation and involves NG-eCall SIP signaling; it may be moderately difficult to exploit.
Blast radius
If exploited, the impact could be significant in terms of data exposure within affected Qualcomm 5G fixed wireless access platforms.
Prioritized remediation
Update firmware to the latest version to address the vulnerability.
info-disc5gfirmwarequalcomm

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-359

Vendors

qualcomm

Products

5g fixed wireless access platform firmware, 5g fixed wireless access platform, ar8035 firmware, ar8035, csra6620 firmware, csra6620, csra6640 firmware, csra6640, fastconnect 6200 firmware, fastconnect 6200, qcs4490 firmware, qcs4490

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.