CVE-2026-25288
Analyzed Analyzed - Analysis Complete

Transient Denial of Service in Qualcomm Chipset Firmware

Vulnerability report for CVE-2026-25288, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-06

Assigner: Qualcomm, Inc.

Description

Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-06
Generated
2026-08-24
AI Q&A
2026-08-04
EPSS Evaluated
2026-08-23
NVD
EUVD

Affected Vendors & Products

Showing 54 associated CPEs
Vendor Product Version / Range
qualcomm orne_firmware *
qualcomm palawan25_firmware *
qualcomm pandeiro_firmware *
qualcomm qln1083bd_firmware *
qualcomm qln1086bd_firmware *
qualcomm qmb715_firmware *
qualcomm qmp1000_firmware *
qualcomm qmp2001_firmware *
qualcomm qpa1083bd_firmware *
qualcomm qpa1086bd_firmware *
qualcomm qxm1093_firmware *
qualcomm qxm1094_firmware *
qualcomm qxm1095_firmware *
qualcomm qxm1096_firmware *
qualcomm sc8380xp_firmware *
qualcomm sm6850_firmware *
qualcomm sm8735p_firmware *
qualcomm sm8845p_firmware *
qualcomm snapdragon_7_gen_4_mobile_platform_firmware *
qualcomm snapdragon_8_elite_gen_5_firmware *
qualcomm wcd9370_firmware *
qualcomm wcd9378_firmware *
qualcomm wcd9378c_firmware *
qualcomm wcd9380_firmware *
qualcomm wcd9385_firmware *
qualcomm wcd9395_firmware *
qualcomm wcn6450_firmware *
qualcomm wcn6755_firmware *
qualcomm wcn7760_firmware *
qualcomm wcn7860_firmware *
qualcomm wcn7861_firmware *
qualcomm wcn7880_firmware *
qualcomm wcn7881_firmware *
qualcomm wsa8840_firmware *
qualcomm wsa8845_firmware *
qualcomm wsa8845h_firmware *
qualcomm wsa8850_firmware *
qualcomm wsa8850w_firmware *
qualcomm wsa8855c_firmware *
qualcomm x2000077_firmware *
qualcomm cologne_firmware *
qualcomm cq7790_firmware *
qualcomm fastconnect_6900_firmware *
qualcomm fastconnect_7800_firmware *
qualcomm molokai_firmware *
qualcomm x2000086_firmware *
qualcomm x2000090_firmware *
qualcomm x2000092_firmware *
qualcomm x2000094_firmware *
qualcomm xg101002_firmware *
qualcomm xg101032_firmware *
qualcomm xg101039_firmware *
qualcomm xrv7209_firmware *
qualcomm xrv9209_firmware *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-126 The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a temporary denial of service (DOS) condition that occurs when processing a short target wake time channel usage response frame with an insufficient packet size. This means an attacker could send a maliciously crafted frame that causes the system to become unresponsive temporarily.

Impact Analysis

This vulnerability could lead to system downtime or degraded performance if exploited. It may cause network devices or systems to stop responding temporarily, disrupting normal operations and potentially leading to loss of service.

Compliance Impact

This vulnerability causes a transient denial of service (DOS) condition, which could disrupt the availability of affected systems. For compliance with standards like GDPR and HIPAA, availability is a key requirement, so such disruptions may lead to non-compliance if not addressed promptly.

Mitigation Strategies

Update affected Qualcomm components to the latest patched versions. Monitor network traffic for malformed target wake time channel usage response frames. Apply vendor-supplied security patches as soon as available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-25288. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart