← Back to search

CVE-2026-25289

9.6 CRITICAL

Published 2026-08-04 · Updated 2026-08-06

AI risk analysis

Summary
The flaw involves memory corruption when processing Device Capability Extended attributes in specific NAN Service Discovery Frames with invalid length values, potentially leading to remote code execution.
Exploitability
Exploitation requires precise manipulation of frame lengths and is moderately difficult due to the need for detailed knowledge of the protocol and valid frame structures.
Blast radius
If exploited, this vulnerability could lead to widespread device compromise across affected Qualcomm firmware versions, impacting a broad range of devices.
Prioritized remediation
Update all affected Qualcomm firmware to the latest version immediately to mitigate the risk.
memory-corruptionremote-code-executionfirmware-update

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-121

Vendors

qualcomm

Products

sm7550p firmware, sm7550p, sm7635p firmware, sm7635p, sm7675 firmware, sm7675, sm7675p firmware, sm7675p, sm8425 firmware, sm8425, sm8550p firmware, sm8550p

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.