CVE-2025-21449: Buffer Over-read in WLAN Embedded SW
Transient DOS may occur while processing malformed length field in SSID IEs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-21449?
CVE-2025-21449 is classified as a Transient Denial of Service (DoS) vulnerability that can occur due to processing malformed length fields in SSID Information Elements (IEs).
How do I fix CVE-2025-21449?
To mitigate CVE-2025-21449, ensure that all affected Qualcomm firmware versions are updated to the latest patched versions as recommended by Qualcomm's security bulletin.
Which devices are affected by CVE-2025-21449?
CVE-2025-21449 affects various Qualcomm firmware versions, including those for Snapdragon, Smart Audio, and other Qualcomm products.
What type of attack can exploit CVE-2025-21449?
An attacker can exploit CVE-2025-21449 by sending malformed packets that can lead to a transient DoS condition on the affected devices.
Is there a workaround for CVE-2025-21449 if immediate patching is not possible?
There are no official workarounds for CVE-2025-21449; it is recommended to apply the firmware updates as soon as possible to mitigate this vulnerability.