HIGH · 8.2

CVE-2025-21427

Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.

Vulnerability Description

Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.

CVSS Score

8.2

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
LOW

Affected Products

VendorProductVersions
QualcommSm6250 Firmware-
QualcommSm6250-
QualcommSm6370 Firmware-
QualcommSm6370-
QualcommSm7315 Firmware-
QualcommSm7315-
QualcommSm7325P Firmware-
QualcommSm7325P-
QualcommSm8550P Firmware-
QualcommSm8550P-
QualcommSmart Display 200 Platform Firmware-
QualcommSmart Display 200 Platform-
QualcommSnapdragon 210 Firmware-
QualcommSnapdragon 210-
QualcommSnapdragon 212 Mobile Firmware-
QualcommSnapdragon 212 Mobile-
QualcommSnapdragon 4 Gen 1 Mobile Firmware-
QualcommSnapdragon 4 Gen 1 Mobile-
QualcommSnapdragon 4 Gen 2 Mobile Firmware-
QualcommSnapdragon 4 Gen 2 Mobile-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-21427?

CVE-2025-21427 is a vulnerability with a CVSS score of 8.2 (HIGH). Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.

How severe is CVE-2025-21427?

CVE-2025-21427 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2025-21427?

Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Sm6250 Firmware, Qualcomm Sm6250, Qualcomm Sm6370 Firmware, Qualcomm Sm6370, Qualcomm Sm7315 Firmware.