Skip to content
CVSS 7.8 · HIGH

CVE-2025-47405

Memory corruption when processing camera sensor input/output control codes with invalid output buffers.

View on NVD

Analysis

This is a low-level firmware vulnerability in specific Qualcomm FastConnect chipsets used in high-end mobile devices. While it involves high-severity memory corruption, it is a hardware-specific issue that requires vendor-level security patches and does not directly affect the software development stack, web servers, or DevOps tooling used by the community.

Severity

Score: 7.8(HIGH)
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AV: LOCAL
AC: LOW
PR: LOW
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-822CWE-119

EPSS

Probability of exploitation (next 30 days): 0.0001 (0.0%)
Percentile: 3.2%
EPSS: 2026-05-06

Affects

qualcomm:fastconnect_6900_firmwarequalcomm:fastconnect_6900qualcomm:fastconnect_7800_firmwarequalcomm:fastconnect_7800qualcomm:iqx5121_firmwarequalcomm:iqx5121qualcomm:iqx7181_firmwarequalcomm:iqx7181qualcomm:qca0000_firmwarequalcomm:qca0000qualcomm:sc8380xp_firmwarequalcomm:sc8380xpqualcomm:sd865_5g_firmwarequalcomm:sd865_5gqualcomm:snapdragon_xr2_5g_firmwarequalcomm:snapdragon_xr2_5gqualcomm:snapdragon_xr2\+_gen_1_firmwarequalcomm:snapdragon_xr2\+_gen_1qualcomm:wcd9380_firmwarequalcomm:wcd9380qualcomm:wcd9385_firmwarequalcomm:wcd9385qualcomm:wsa8810_firmwarequalcomm:wsa8810qualcomm:wsa8815_firmwarequalcomm:wsa8815qualcomm:wsa8840_firmwarequalcomm:wsa8840qualcomm:wsa8845_firmwarequalcomm:wsa8845qualcomm:wsa8845h_firmwarequalcomm:wsa8845h

Technical description

Memory corruption when processing camera sensor input/output control codes with invalid output buffers.

Published: 5/4/2026, 5:16:20 PM
Last modified: 5/6/2026, 6:03:08 PM

References

HomeEventsBlogResourcesTeam