CVE-2025-27034
BaseFortify
Publication date: 2025-09-24
Last updated on: 2025-11-28
Assigner: Qualcomm, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| qualcomm | fastconnect_6900_firmware | * |
| qualcomm | fastconnect_6900 | * |
| qualcomm | fastconnect_7800_firmware | * |
| qualcomm | fastconnect_7800 | * |
| qualcomm | qca6174a_firmware | * |
| qualcomm | qca6174a | * |
| qualcomm | qca6391_firmware | * |
| qualcomm | qca6391 | * |
| qualcomm | qca6574a_firmware | * |
| qualcomm | qca6574a | * |
| qualcomm | qca6584au_firmware | * |
| qualcomm | qca6584au | * |
| qualcomm | qca6595au_firmware | * |
| qualcomm | qca6595au | * |
| qualcomm | qca6696_firmware | * |
| qualcomm | qca6696 | * |
| qualcomm | qca6698aq_firmware | * |
| qualcomm | qca6698aq | * |
| qualcomm | qca8081_firmware | * |
| qualcomm | qca8081 | * |
| qualcomm | qca8337_firmware | * |
| qualcomm | qca8337 | * |
| qualcomm | qcc710_firmware | * |
| qualcomm | qcc710 | * |
| qualcomm | qcm4490_firmware | * |
| qualcomm | qcm4490 | * |
| qualcomm | qcm5430_firmware | * |
| qualcomm | qcm5430 | * |
| qualcomm | qcm6490_firmware | * |
| qualcomm | qcm6490 | * |
| qualcomm | qcm8550_firmware | * |
| qualcomm | qcm8550 | * |
| qualcomm | qcn6024_firmware | * |
| qualcomm | qcn6024 | * |
| qualcomm | qcn6224_firmware | * |
| qualcomm | qcn6224 | * |
| qualcomm | qcn6274_firmware | * |
| qualcomm | qcn6274 | * |
| qualcomm | qcn9024_firmware | * |
| qualcomm | qcn9024 | * |
| qualcomm | qcs4490_firmware | * |
| qualcomm | qcs4490 | * |
| qualcomm | qcs5430_firmware | * |
| qualcomm | qcs5430 | * |
| qualcomm | qcs6490_firmware | * |
| qualcomm | qcs6490 | * |
| qualcomm | qcs8550_firmware | * |
| qualcomm | qcs8550 | * |
| qualcomm | qep8111_firmware | * |
| qualcomm | qep8111 | * |
| qualcomm | qfw7114_firmware | * |
| qualcomm | qfw7114 | * |
| qualcomm | qfw7124_firmware | * |
| qualcomm | qfw7124 | * |
| qualcomm | video_collaboration_vc3_platform_firmware | * |
| qualcomm | video_collaboration_vc3_platform | * |
| qualcomm | sd_8_gen1_5g_firmware | * |
| qualcomm | sd_8_gen1_5g | * |
| qualcomm | sdx55_firmware | * |
| qualcomm | sdx55 | * |
| qualcomm | sdx57m_firmware | * |
| qualcomm | sdx57m | * |
| qualcomm | sdx61_firmware | * |
| qualcomm | sdx61 | * |
| qualcomm | sdx71m_firmware | * |
| qualcomm | sdx71m | * |
| qualcomm | sdx80m_firmware | * |
| qualcomm | sdx80m | * |
| qualcomm | sg8275p_firmware | * |
| qualcomm | sg8275p | * |
| qualcomm | sm4635_firmware | * |
| qualcomm | sm4635 | * |
| qualcomm | sm6650_firmware | * |
| qualcomm | sm6650 | * |
| qualcomm | sm7250p_firmware | * |
| qualcomm | sm7250p | * |
| qualcomm | sm7325p_firmware | * |
| qualcomm | sm7325p | * |
| qualcomm | sm7635_firmware | * |
| qualcomm | sm7635 | * |
| qualcomm | 315_5g_iot_modem_firmware | * |
| qualcomm | 315_5g_iot_modem | * |
| qualcomm | ar8035_firmware | * |
| qualcomm | ar8035 | * |
| qualcomm | fastconnect_6200_firmware | * |
| qualcomm | fastconnect_6200 | * |
| qualcomm | fastconnect_6700_firmware | * |
| qualcomm | fastconnect_6700 | * |
| qualcomm | fastconnect_6800_firmware | * |
| qualcomm | fastconnect_6800 | * |
| qualcomm | sm7675_firmware | * |
| qualcomm | sm7675 | * |
| qualcomm | sm7675p_firmware | * |
| qualcomm | sm7675p | * |
| qualcomm | sm8550p_firmware | * |
| qualcomm | sm8550p | * |
| qualcomm | sm8635_firmware | * |
| qualcomm | sm8635 | * |
| qualcomm | sm8635p_firmware | * |
| qualcomm | sm8635p | * |
| qualcomm | sm8650q_firmware | * |
| qualcomm | sm8650q | * |
| qualcomm | sm8750_firmware | * |
| qualcomm | sm8750 | * |
| qualcomm | sm8750p_firmware | * |
| qualcomm | sm8750p | * |
| qualcomm | snapdragon_4_gen_1_mobile_platform_firmware | * |
| qualcomm | snapdragon_4_gen_1_mobile_platform | * |
| qualcomm | snapdragon_480_5g_mobile_platform_firmware | * |
| qualcomm | snapdragon_480_5g_mobile_platform | * |
| qualcomm | snapdragon_480\+_5g_mobile_platform_\(sm4350-ac\)_firmware | * |
| qualcomm | snapdragon_480\+_5g_mobile_platform_\(sm4350-ac\) | * |
| qualcomm | snapdragon_690_5g_mobile_platform_firmware | * |
| qualcomm | snapdragon_690_5g_mobile_platform | * |
| qualcomm | snapdragon_695_5g_mobile_platform_firmware | * |
| qualcomm | snapdragon_695_5g_mobile_platform | * |
| qualcomm | snapdragon_765_5g_mobile_platform_\(sm7250-aa\)_firmware | * |
| qualcomm | snapdragon_765_5g_mobile_platform_\(sm7250-aa\) | * |
| qualcomm | snapdragon_765g_5g_mobile_platform_\(sm7250-ab\)_firmware | * |
| qualcomm | snapdragon_765g_5g_mobile_platform_\(sm7250-ab\) | * |
| qualcomm | snapdragon_768g_5g_mobile_platform_\(sm7250-ac\)_firmware | * |
| qualcomm | snapdragon_768g_5g_mobile_platform_\(sm7250-ac\) | * |
| qualcomm | snapdragon_778g_5g_mobile_platform_firmware | * |
| qualcomm | snapdragon_778g_5g_mobile_platform | * |
| qualcomm | snapdragon_778g\+_5g_mobile_platform_\(sm7325-ae\)_firmware | * |
| qualcomm | snapdragon_778g\+_5g_mobile_platform_\(sm7325-ae\) | * |
| qualcomm | snapdragon_780g_5g_mobile_platform_firmware | * |
| qualcomm | snapdragon_780g_5g_mobile_platform | * |
| qualcomm | snapdragon_782g_mobile_platform_\(sm7325-af\)_firmware | * |
| qualcomm | snapdragon_782g_mobile_platform_\(sm7325-af\) | * |
| qualcomm | snapdragon_7c\+_gen_3_compute_firmware | * |
| qualcomm | snapdragon_7c\+_gen_3_compute | * |
| qualcomm | snapdragon_8_gen_1_mobile_platform_firmware | * |
| qualcomm | snapdragon_8_gen_1_mobile_platform | * |
| qualcomm | snapdragon_8_gen_2_mobile_platform_firmware | * |
| qualcomm | snapdragon_8_gen_2_mobile_platform | * |
| qualcomm | snapdragon_8_gen_3_mobile_platform_firmware | * |
| qualcomm | snapdragon_8_gen_3_mobile_platform | * |
| qualcomm | snapdragon_8\+_gen_1_mobile_platform_firmware | * |
| qualcomm | snapdragon_8\+_gen_1_mobile_platform | * |
| qualcomm | snapdragon_8\+_gen_2_mobile_platform_firmware | * |
| qualcomm | snapdragon_8\+_gen_2_mobile_platform | * |
| qualcomm | snapdragon_865_5g_mobile_platform_firmware | * |
| qualcomm | snapdragon_865_5g_mobile_platform | * |
| qualcomm | snapdragon_865\+_5g_mobile_platform_\(sm8250-ab\)_firmware | * |
| qualcomm | snapdragon_865\+_5g_mobile_platform_\(sm8250-ab\) | * |
| qualcomm | snapdragon_870_5g_mobile_platform_\(sm8250-ac\)_firmware | * |
| qualcomm | snapdragon_870_5g_mobile_platform_\(sm8250-ac\) | * |
| qualcomm | snapdragon_888_5g_mobile_platform_firmware | * |
| qualcomm | snapdragon_888_5g_mobile_platform | * |
| qualcomm | snapdragon_888\+_5g_mobile_platform_\(sm8350-ac\)_firmware | * |
| qualcomm | snapdragon_888\+_5g_mobile_platform_\(sm8350-ac\) | * |
| qualcomm | snapdragon_auto_5g_modem-rf_firmware | * |
| qualcomm | snapdragon_auto_5g_modem-rf | * |
| qualcomm | snapdragon_auto_5g_modem-rf_gen_2_firmware | * |
| qualcomm | snapdragon_auto_5g_modem-rf_gen_2 | * |
| qualcomm | snapdragon_x35_5g_modem-rf_system_firmware | * |
| qualcomm | snapdragon_x35_5g_modem-rf_system | * |
| qualcomm | snapdragon_x55_5g_modem-rf_system_firmware | * |
| qualcomm | snapdragon_x55_5g_modem-rf_system | * |
| qualcomm | snapdragon_x62_5g_modem-rf_system_firmware | * |
| qualcomm | snapdragon_x62_5g_modem-rf_system | * |
| qualcomm | snapdragon_x65_5g_modem-rf_system_firmware | * |
| qualcomm | snapdragon_x65_5g_modem-rf_system | * |
| qualcomm | snapdragon_x70_modem-rf_system_firmware | * |
| qualcomm | snapdragon_x70_modem-rf_system | * |
| qualcomm | snapdragon_x72_5g_modem-rf_system_firmware | * |
| qualcomm | snapdragon_x72_5g_modem-rf_system | * |
| qualcomm | snapdragon_x75_5g_modem-rf_system_firmware | * |
| qualcomm | snapdragon_x75_5g_modem-rf_system | * |
| qualcomm | wcd9340_firmware | * |
| qualcomm | wcd9340 | * |
| qualcomm | wcd9341_firmware | * |
| qualcomm | wcd9341 | * |
| qualcomm | wcd9360_firmware | * |
| qualcomm | wcd9360 | * |
| qualcomm | wcd9370_firmware | * |
| qualcomm | wcd9370 | * |
| qualcomm | wcd9375_firmware | * |
| qualcomm | wcd9375 | * |
| qualcomm | wcd9378_firmware | * |
| qualcomm | wcd9378 | * |
| qualcomm | wcd9380_firmware | * |
| qualcomm | wcd9380 | * |
| qualcomm | wcd9385_firmware | * |
| qualcomm | wcd9385 | * |
| qualcomm | wcd9390_firmware | * |
| qualcomm | wcd9390 | * |
| qualcomm | wcd9395_firmware | * |
| qualcomm | wcd9395 | * |
| qualcomm | wcn3950_firmware | * |
| qualcomm | wcn3950 | * |
| qualcomm | wcn3988_firmware | * |
| qualcomm | wcn3988 | * |
| qualcomm | wcn6450_firmware | * |
| qualcomm | wcn6450 | * |
| qualcomm | wcn6650_firmware | * |
| qualcomm | wcn6650 | * |
| qualcomm | wcn6740_firmware | * |
| qualcomm | wcn6740 | * |
| qualcomm | wcn6755_firmware | * |
| qualcomm | wcn6755 | * |
| qualcomm | wcn7860_firmware | * |
| qualcomm | wcn7860 | * |
| qualcomm | wcn7861_firmware | * |
| qualcomm | wcn7861 | * |
| qualcomm | wcn7880_firmware | * |
| qualcomm | wcn7880 | * |
| qualcomm | wcn7881_firmware | * |
| qualcomm | wcn7881 | * |
| qualcomm | wsa8810_firmware | * |
| qualcomm | wsa8810 | * |
| qualcomm | wsa8815_firmware | * |
| qualcomm | wsa8815 | * |
| qualcomm | wsa8830_firmware | * |
| qualcomm | wsa8830 | * |
| qualcomm | wsa8832_firmware | * |
| qualcomm | wsa8832 | * |
| qualcomm | wsa8835_firmware | * |
| qualcomm | wsa8835 | * |
| qualcomm | wsa8840_firmware | * |
| qualcomm | wsa8840 | * |
| qualcomm | wsa8845_firmware | * |
| qualcomm | wsa8845 | * |
| qualcomm | wsa8845h_firmware | * |
| qualcomm | wsa8845h | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-129 | The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a memory corruption issue that occurs when selecting the Public Land Mobile Network (PLMN) from the SOR (Selected Operator Repository) failed list. This means that during the process of choosing a network from a list of previously failed networks, the system improperly handles memory, which can lead to unexpected behavior or exploitation.
How can this vulnerability impact me? :
The vulnerability has a high severity score (CVSS 9.8) indicating it can be exploited remotely without privileges or user interaction, potentially leading to complete compromise of confidentiality, integrity, and availability. This means an attacker could execute arbitrary code, cause denial of service, or access sensitive information on affected devices.