Vulnerability Description
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the run_cmd argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.7 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This issue affects Quantenna Wi-Fi chipset through version 8.0.0.28 of the latest SDK, and appears to be unpatched at the time of this CVE record's first publishing, though the vendor has released a best practices guide for implementors of this chipset.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Onsemi | Qcs-Ax3-S5 Firmware | - |
| Onsemi | Qcs-Ax3-S5 | - |
| Onsemi | Qcs-Ax2-A12 Firmware | - |
| Onsemi | Qcs-Ax2-A12 | - |
| Onsemi | Qcs-Ax2-T12 Firmware | - |
| Onsemi | Qcs-Ax2-T12 | - |
| Onsemi | Qcs-Ax2-T8 Firmware | - |
| Onsemi | Qcs-Ax2-T8 | - |
| Onsemi | Qd840 Firmware | - |
| Onsemi | Qd840 | - |
| Onsemi | Qhs710 Firmware | - |
| Onsemi | Qhs710 | - |
| Onsemi | Qsr10Ga Firmware | - |
| Onsemi | Qsr10Ga | - |
| Onsemi | Qsr10Gu Firmware | - |
| Onsemi | Qsr10Gu | - |
| Onsemi | Qv840 Firmware | - |
| Onsemi | Qv840 | - |
| Onsemi | Qv840C Firmware | - |
| Onsemi | Qv840C | - |
Related Weaknesses (CWE)
References
- https://community.onsemi.com/s/article/QCS-Quantenna-Wi-Fi-product-support-and-sRelease Notes
- https://takeonme.org/cves/cve-2025-3460Not Applicable
FAQ
What is CVE-2025-32455?
CVE-2025-32455 is a vulnerability with a CVSS score of 7.7 (HIGH). The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the run_cmd argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutraliza...
How severe is CVE-2025-32455?
CVE-2025-32455 has been rated HIGH with a CVSS base score of 7.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-32455?
Check the references section above for vendor advisories and patch information. Affected products include: Onsemi Qcs-Ax3-S5 Firmware, Onsemi Qcs-Ax3-S5, Onsemi Qcs-Ax2-A12 Firmware, Onsemi Qcs-Ax2-A12, Onsemi Qcs-Ax2-T12 Firmware.