CVE-2026-25254: Improper authorization in Qualcomm Software Center
Published Sep 22, 2026
·Updated
Improper authorization leads to Remote Code Execution via SocketIO interface.
Affected Software
1 affected component
Qualcomm Software Center
Event History
Sep 22, 2026
CVE Published
via MITRE·09:45 AM
Data Sourced
via MITRE·09:45 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The CVSS vector indicates network access, low attack complexity, no prior privileges, and no user interaction are required.
2
What is the potential impact if exploitation succeeds?
The reported impact is high for confidentiality, integrity, and availability. The CVSS vector indicates the scope is unchanged.