Skip to content
CVSS 7.8 · HIGH

CVE-2025-47405

Memory corruption when processing camera sensor input/output control codes with invalid output buffers.

Ver en NVD

Análisis

This is a low-level firmware vulnerability in specific Qualcomm FastConnect chipsets used in high-end mobile devices. While it involves high-severity memory corruption, it is a hardware-specific issue that requires vendor-level security patches and does not directly affect the software development stack, web servers, or DevOps tooling used by the community.

Severidad

Puntaje: 7.8(HIGH)
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AV: LOCAL
AC: LOW
PR: LOW
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE): CWE-822CWE-119

EPSS

Probabilidad de explotación (próx. 30 días): 0.0001 (0.0%)
Percentil: 3.2%
EPSS: 2026-05-06

Afecta

qualcomm:fastconnect_6900_firmwarequalcomm:fastconnect_6900qualcomm:fastconnect_7800_firmwarequalcomm:fastconnect_7800qualcomm:iqx5121_firmwarequalcomm:iqx5121qualcomm:iqx7181_firmwarequalcomm:iqx7181qualcomm:qca0000_firmwarequalcomm:qca0000qualcomm:sc8380xp_firmwarequalcomm:sc8380xpqualcomm:sd865_5g_firmwarequalcomm:sd865_5gqualcomm:snapdragon_xr2_5g_firmwarequalcomm:snapdragon_xr2_5gqualcomm:snapdragon_xr2\+_gen_1_firmwarequalcomm:snapdragon_xr2\+_gen_1qualcomm:wcd9380_firmwarequalcomm:wcd9380qualcomm:wcd9385_firmwarequalcomm:wcd9385qualcomm:wsa8810_firmwarequalcomm:wsa8810qualcomm:wsa8815_firmwarequalcomm:wsa8815qualcomm:wsa8840_firmwarequalcomm:wsa8840qualcomm:wsa8845_firmwarequalcomm:wsa8845qualcomm:wsa8845h_firmwarequalcomm:wsa8845h

Descripción técnica

Memory corruption when processing camera sensor input/output control codes with invalid output buffers.

Publicada: 4/5/2026, 17:16:20
Última modificación: 6/5/2026, 18:03:08

Referencias

InicioEventosBlogRecursosEquipo