Home

Description

Information disclosure while opening a fastrpc session when domain is not sanitized.

PUBLISHED Reserved 2024-12-18 | Published 2025-08-06 | Updated 2025-08-06 | Assigner qualcomm




MEDIUM: 6.1CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

Problem types

CWE-126 Buffer Over-read

Product status

Default status
unaffected

AR8035
affected

FastConnect 7800
affected

QCA6584AU
affected

QCA6698AQ
affected

QCA8081
affected

QCA8337
affected

QCC710
affected

QCN6224
affected

QCN6274
affected

QFW7114
affected

QFW7124
affected

Snapdragon Auto 5G Modem-RF Gen 2
affected

Snapdragon X72 5G Modem-RF System
affected

Snapdragon X75 5G Modem-RF System
affected

WCD9340
affected

References

docs.qualcomm.com/...uritybulletin/august-2025-bulletin.html

cve.org (CVE-2025-21457)

nvd.nist.gov (CVE-2025-21457)

Download JSON