CVE-2025-21488

HIGH

Qualcomm Fastconnect 6200 Firmware - Buffer Over-read

Title source: rule
STIX 2.1

Description

Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.

Scores

CVSS v3 8.2
EPSS 0.0005
EPSS Percentile 15.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-126
Status published
Products (50)
qualcomm/fastconnect_6200_firmware
qualcomm/fastconnect_6700_firmware
qualcomm/fastconnect_6900_firmware
qualcomm/fastconnect_7800_firmware
qualcomm/msm8996au_firmware
qualcomm/qca6564_firmware
qualcomm/qca6564a_firmware
qualcomm/qca6564au_firmware
qualcomm/qca6574_firmware
qualcomm/qca6574a_firmware
... and 40 more
Published Sep 24, 2025
Tracked Since Feb 18, 2026