Vulnerability Description
The Quantenna Wi-Fi chips ship with an unauthenticated telnet interface by default. This is an instance of CWE-306, "Missing Authentication for Critical Function," and is estimated as a CVSS 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This issue affects Quantenna Wi-Fi chipset through version 8.0.0.28 of the latest SDK, and appears to be unpatched at the time of this CVE record's first publishing, though the vendor has released a best practices guide for implementors of this chipset.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Onsemi | Qhs710 Firmware | - |
| Onsemi | Qhs710 | - |
| Onsemi | Qsr10Ga Firmware | - |
| Onsemi | Qsr10Ga | - |
| Onsemi | Qsr10Gu Firmware | - |
| Onsemi | Qsr10Gu | - |
| Onsemi | Qv840 Firmware | - |
| Onsemi | Qv840 | - |
| Onsemi | Qv840C Firmware | - |
| Onsemi | Qv840C | - |
| Onsemi | Qv860 Firmware | - |
| Onsemi | Qv860 | - |
| Onsemi | Qv940 Firmware | - |
| Onsemi | Qv940 | - |
| Onsemi | Qv942C Firmware | - |
| Onsemi | Qv942C | - |
| Onsemi | Qv952C Firmware | - |
| Onsemi | Qv952C | - |
| Onsemi | Qcs-Ax2-S5 Firmware | - |
| Onsemi | Qcs-Ax2-S5 | - |
Related Weaknesses (CWE)
References
- https://community.onsemi.com/s/article/QCS-Quantenna-Wi-Fi-product-support-and-sRelease Notes
- https://takeonme.org/cves/cve-2025-3461/ExploitThird Party Advisory
FAQ
What is CVE-2025-3461?
CVE-2025-3461 is a vulnerability with a CVSS score of 9.1 (CRITICAL). The Quantenna Wi-Fi chips ship with an unauthenticated telnet interface by default. This is an instance of CWE-306, "Missing Authentication for Critical Function," and is estimated as a CVSS 9.1 (CVSS...
How severe is CVE-2025-3461?
CVE-2025-3461 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-3461?
Check the references section above for vendor advisories and patch information. Affected products include: Onsemi Qhs710 Firmware, Onsemi Qhs710, Onsemi Qsr10Ga Firmware, Onsemi Qsr10Ga, Onsemi Qsr10Gu Firmware.