Skip to content
CVSS 9.6 · CRITICAL

CVE-2026-25293

Buffer overflow due to incorrect authorization in PLC FW

View on NVD

Analysis

This vulnerability affects Qualcomm QCA7005 Powerline Communication firmware, which is a specialized hardware component used primarily in automotive and industrial IoT applications. It is not relevant to the general web, mobile, or backend software development stacks used by the community. Although the severity is critical, the impact is limited to niche hardware deployments.

Severity

Score: 9.6(CRITICAL)
Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: ADJACENT_NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-863

EPSS

Probability of exploitation (next 30 days): 0.0002 (0.0%)
Percentile: 5.7%
EPSS: 2026-05-06

Affects

qualcomm:qca7005_firmwarequalcomm:qca7005

Technical description

Buffer overflow due to incorrect authorization in PLC FW

Published: 5/4/2026, 5:16:22 PM
Last modified: 5/6/2026, 6:01:11 PM

References

HomeEventsBlogResourcesTeam