Qualcomm WLAN Buffer Over-Read Vulnerability Leading to Transient Denial-of-Service

Vulnerability

A buffer over-read vulnerability has been identified in the WLAN firmware of various chipsets. This vulnerability can cause a transient denial-of-service condition by processing malformed length fields in SSID information elements, particularly when handling beacon frames or WLAN frames for BTM requests.

Impact

Exploitation of this vulnerability can lead to a transient denial-of-service condition, causing the device to temporarily become unresponsive or unavailable.

Remediation

Qualcomm has released patches for this vulnerability. Instructions for applying the patch can be found in the Qualcomm July 2025 Security Bulletin.

Added: Jul 8, 2025, 3:14 PM
Updated: Jul 8, 2025, 3:14 PM

Vulnerability Rating

Custom Algorithm
spread
8.7
impact
2.5
exploitability
7.0
remediation
8.3
relevance
0.2
threat
0.0
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.