CVE-2025-47372
CRITICALQualcomm Qam8255p Firmware - Out-of-Bounds Write
Title source: ruleDescription
Memory Corruption when a corrupted ELF image with an oversized file size is read into a buffer without authentication.
Scores
CVSS v3
9.0
EPSS
0.0001
EPSS Percentile
2.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-120
CWE-787
Status
published
Products (23)
qualcomm/qam8255p_firmware
qualcomm/qam8620p_firmware
qualcomm/qam8650p_firmware
qualcomm/qam8775p_firmware
qualcomm/qamsrv1h_firmware
qualcomm/qamsrv1m_firmware
qualcomm/qca6595_firmware
qualcomm/qca6595au_firmware
qualcomm/qca6678aq_firmware
qualcomm/qca6696_firmware
... and 13 more
Published
Dec 18, 2025
Tracked Since
Feb 18, 2026