Qualcomm Products Buffer Over-read Vulnerability in WLAN Host

Vulnerability

A buffer over-read vulnerability has been identified in various chipsets used in Qualcomm products. This vulnerability can lead to a transient denial-of-service condition by improperly parsing Extended Header Information (EHT) operation or capability elements, potentially causing a device to reset during a video call.

Impact

Exploitation of this vulnerability can cause a transient denial-of-service condition, where the device resets due to the improper handling of non-conforming RTCP packets during a video call.

Remediation

Qualcomm has released patches for this vulnerability. Instructions for applying the patch can be found in the Qualcomm April 2025 Security Bulletin.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
0.6
exploitability
7.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.