CVSS 9.6 · CRITICAL
CVE-2026-25293
Buffer overflow due to incorrect authorization in PLC FW
View on NVDAnalysis
This vulnerability affects Qualcomm QCA7005 Powerline Communication firmware, which is a specialized hardware component used primarily in automotive and industrial IoT applications. It is not relevant to the general web, mobile, or backend software development stacks used by the community. Although the severity is critical, the impact is limited to niche hardware deployments.
Severity
Score: 9.6(CRITICAL)
Vector:
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HAV: ADJACENT_NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE):
CWE-863EPSS
Probability of exploitation (next 30 days): 0.0002 (0.0%)
Percentile: 5.7%
EPSS: 2026-05-06
Affects
qualcomm:qca7005_firmwarequalcomm:qca7005Technical description
Buffer overflow due to incorrect authorization in PLC FW
Published: 5/4/2026, 5:16:22 PM
Last modified: 5/6/2026, 6:01:11 PM