CVE-2025-59601
Analyzed
Analyzed - Analysis Complete
Information Disclosure in Qualcomm Powerline Device Firmware
Publication date: 2026-06-01
Last updated on: 2026-06-02
Assigner: Qualcomm, Inc.
Description
Description
Information Disclosure when resetting device to factory default settings through powerline interface allows unauthorized access to device configuration.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| qualcomm | fastconnect_7800_firmware | * |
| qualcomm | qca7005_firmware | * |
| qualcomm | snapdragon_ar1_gen_1_platform_firmware | * |
| qualcomm | wcd9380_firmware | * |
| qualcomm | wcd9385_firmware | * |
| qualcomm | wsa8830_firmware | * |
| qualcomm | wsa8832_firmware | * |
| qualcomm | wsa8835_firmware | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1230 | The product prevents direct access to a resource containing sensitive information, but it does not sufficiently limit access to metadata that is derived from the original, sensitive information. |