Qualcomm Products Buffer Over-Read Vulnerability in WLAN HAL Power Control Processing

Vulnerability

A buffer over-read vulnerability has been identified in the WLAN Hardware Abstraction Layer (HAL) of various chipsets, including those used in automotive software platforms and video applications. This vulnerability leads to a transient denial-of-service condition by improperly handling command data during power control processing, particularly when invalid antenna or stream values are introduced.

Impact

Exploitation of this vulnerability causes a temporary denial-of-service condition by disrupting normal power control processes, which could lead to broader connectivity issues.

Remediation

Qualcomm has notified device manufacturers about this vulnerability and is actively sharing patch information. Instructions for applying the patch can be found in the September 2025 Qualcomm Security Bulletin.

Added: Sep 24, 2025, 7:27 PM
Updated: Sep 24, 2025, 7:27 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
0.6
exploitability
5.4
remediation
7.7
relevance
0.6
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.