CVE-2022-25708

CRITICAL

Qualcomm SD 8 Gen1 5G Firmware - Buffer Overflow

Title source: rule
STIX 2.1

Description

Memory corruption in WLAN due to buffer copy without checking size of input while parsing keys in Snapdragon Connectivity, Snapdragon Mobile

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0037
EPSS Percentile 58.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-120
Status published
Products (17)
qualcomm/sd888_5g_firmware
qualcomm/sd_8_gen1_5g_firmware
qualcomm/sm7450_firmware
qualcomm/wcd9370_firmware
qualcomm/wcd9375_firmware
qualcomm/wcd9380_firmware
qualcomm/wcd9385_firmware
qualcomm/wcn6750_firmware
qualcomm/wcn6850_firmware
qualcomm/wcn6851_firmware
... and 7 more
Published Sep 16, 2022
Tracked Since Feb 18, 2026