CVE-2025-59601
Analyzed Analyzed - Analysis Complete
Information Disclosure in Qualcomm Powerline Device Firmware

Publication date: 2026-06-01

Last updated on: 2026-06-02

Assigner: Qualcomm, Inc.

Description
Information Disclosure when resetting device to factory default settings through powerline interface allows unauthorized access to device configuration.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-01
Last Modified
2026-06-02
Generated
2026-06-22
AI Q&A
2026-06-02
EPSS Evaluated
2026-06-21
NVD
EUVD
Affected Vendors & Products
Showing 8 associated CPEs
Vendor Product Version / Range
qualcomm fastconnect_7800_firmware *
qualcomm qca7005_firmware *
qualcomm snapdragon_ar1_gen_1_platform_firmware *
qualcomm wcd9380_firmware *
qualcomm wcd9385_firmware *
qualcomm wsa8830_firmware *
qualcomm wsa8832_firmware *
qualcomm wsa8835_firmware *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1230 The product prevents direct access to a resource containing sensitive information, but it does not sufficiently limit access to metadata that is derived from the original, sensitive information.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Impact Analysis

The vulnerability can lead to unauthorized access to sensitive device configuration information. This could allow attackers to learn about device settings, potentially enabling further attacks or misuse of the device.

Executive Summary

This vulnerability involves information disclosure that occurs when a device is reset to its factory default settings through the powerline interface. During this reset process, unauthorized users can gain access to the device's configuration.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-59601. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart