← Back to search

CVE-2026-25292

7.6 HIGH

Published 2026-08-04 · Updated 2026-08-06

AI risk analysis

Summary
The flaw involves memory corruption due to improper handling of untrusted user input in the fastboot command handler for audio framework configuration, which can lead to arbitrary code execution.
Exploitability
Exploitation requires access to the device via fastboot and manipulation of audio framework configuration commands; technical expertise is needed.
Blast radius
If exploited, this could allow an attacker to gain full control over affected Qualcomm devices, leading to severe security implications.
Prioritized remediation
Update firmware to the latest version available from the manufacturer to patch the vulnerability.
rcefirmwarememory-corruption

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-1286

Vendors

qualcomm

Products

sm6225p firmware, sm6225p, sm6450p firmware, sm6450p, sm6475p firmware, sm6475p, sm6475q firmware, sm6475q, sm6850 firmware, sm6850, sm7435 firmware, sm7435

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.