HIGH · 7.5

CVE-2025-21449

Transient DOS may occur while processing malformed length field in SSID IEs.

Vulnerability Description

Transient DOS may occur while processing malformed length field in SSID IEs.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
QualcommSm8635P Firmware-
QualcommSm8635P-
QualcommSm8650Q Firmware-
QualcommSm8650Q-
QualcommSm8735 Firmware-
QualcommSm8735-
QualcommSm8750 Firmware-
QualcommSm8750-
QualcommSm8750P Firmware-
QualcommSm8750P-
QualcommSmart Audio 200 Platform Firmware-
QualcommSmart Audio 200 Platform-
QualcommSmart Audio 400 Platform Firmware-
QualcommSmart Audio 400 Platform-
QualcommSnapdragon 4 Gen 1 Mobile Firmware-
QualcommSnapdragon 4 Gen 1 Mobile-
QualcommSnapdragon 4 Gen 2 Mobile Firmware-
QualcommSnapdragon 4 Gen 2 Mobile-
QualcommSnapdragon 460 Mobile Firmware-
QualcommSnapdragon 460 Mobile-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-21449?

CVE-2025-21449 is a vulnerability with a CVSS score of 7.5 (HIGH). Transient DOS may occur while processing malformed length field in SSID IEs.

How severe is CVE-2025-21449?

CVE-2025-21449 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2025-21449?

Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Sm8635P Firmware, Qualcomm Sm8635P, Qualcomm Sm8650Q Firmware, Qualcomm Sm8650Q, Qualcomm Sm8735 Firmware.