CVE-2026-25275: Buffer Over-read in WLAN Firmware
Published Sep 17, 2026
·Updated
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
Event History
Sep 17, 2026
CVE Published
via MITRE·04:11 AM
Data Sourced
via MITRE·04:11 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does an attacker need credentials or user interaction to trigger the issue?
No. The CVSS vector indicates network access, low attack complexity, no privileges required, and no user interaction.
2
What is the expected security impact?
The reported impact is a transient denial of service. The CVSS vector indicates no confidentiality or integrity impact, with high availability impact.