Record summary

CVE-2026-25289 has a selected CVSS score of 9.6 (critical).

Description

Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 4, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListAR8035affected
Cologneaffected
CQ7790affected
CQ8725Saffected
CQ8750Maffected
FastConnect 6200affected
FastConnect 6700affected
FastConnect 6800affected
FastConnect 6900affected
FastConnect 7800affected
FWA Gen 3 Ultra Platformaffected
FWA Gen 5 Elite Platformaffected
Showing 12 of 188 version ranges

References

2