MEDIUM · 5.5

CVE-2025-59609

Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.

Vulnerability Description

Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.

CVSS Score

5.5

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
Qualcomm5G Fixed Wireless Access Platform Firmware-
Qualcomm5G Fixed Wireless Access Platform-
QualcommAr8035 Firmware-
QualcommAr8035-
QualcommCsr8811 Firmware-
QualcommCsr8811-
QualcommFastconnect 6700 Firmware-
QualcommFastconnect 6700-
QualcommFastconnect 6900 Firmware-
QualcommFastconnect 6900-
QualcommSxr2250P Firmware-
QualcommSxr2250P-
QualcommWcd9340 Firmware-
QualcommWcd9340-
QualcommWcd9370 Firmware-
QualcommWcd9370-
QualcommWcd9371 Firmware-
QualcommWcd9371-
QualcommWcd9375 Firmware-
QualcommWcd9375-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-59609?

CVE-2025-59609 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.

How severe is CVE-2025-59609?

CVE-2025-59609 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2025-59609?

Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm 5G Fixed Wireless Access Platform Firmware, Qualcomm 5G Fixed Wireless Access Platform, Qualcomm Ar8035 Firmware, Qualcomm Ar8035, Qualcomm Csr8811 Firmware.