CVE-2025-21457
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-08-06
Last updated on: 2025-08-19
Assigner: Qualcomm, Inc.
Description
Description
Information disclosure while opening a fastrpc session when domain is not sanitized.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| qualcomm | ar8035_firmware | * |
| qualcomm | ar8035 | * |
| qualcomm | fastconnect_7800_firmware | * |
| qualcomm | fastconnect_7800 | * |
| qualcomm | qca6584au_firmware | * |
| qualcomm | qca6584au | * |
| qualcomm | qca6698aq_firmware | * |
| qualcomm | qca6698aq | * |
| qualcomm | qca8081_firmware | * |
| qualcomm | qca8081 | * |
| qualcomm | qca8337_firmware | * |
| qualcomm | qca8337 | * |
| qualcomm | qcc710_firmware | * |
| qualcomm | qcc710 | * |
| qualcomm | qcn6224_firmware | * |
| qualcomm | qcn6224 | * |
| qualcomm | qcn6274_firmware | * |
| qualcomm | qcn6274 | * |
| qualcomm | qfw7114_firmware | * |
| qualcomm | qfw7114 | * |
| qualcomm | qfw7124_firmware | * |
| qualcomm | qfw7124 | * |
| qualcomm | snapdragon_auto_5g_modem-rf_gen_2_firmware | * |
| qualcomm | snapdragon_auto_5g_modem-rf_gen_2 | * |
| qualcomm | snapdragon_x72_5g_modem-rf_system_firmware | * |
| qualcomm | snapdragon_x72_5g_modem-rf_system | * |
| qualcomm | snapdragon_x75_5g_modem-rf_system_firmware | * |
| qualcomm | snapdragon_x75_5g_modem-rf_system | * |
| qualcomm | wcd9340_firmware | * |
| qualcomm | wcd9340 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-126 | The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves information disclosure that occurs when opening a fastrpc session if the domain is not properly sanitized. This means that improper handling of domain input can lead to unintended exposure of sensitive information.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized disclosure of sensitive information, potentially compromising confidentiality. This could affect the security of systems relying on fastrpc sessions by exposing data that should remain private.
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70