HIGH · 8.8

CVE-2026-25268

Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.

Vulnerability Description

Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
QualcommWsa8835 Firmware-
QualcommWsa8835-
Qualcomm5G Fixed Wireless Access Platform Firmware-
Qualcomm5G Fixed Wireless Access Platform-
QualcommAr8035 Firmware-
QualcommAr8035-
QualcommCq7790 Firmware-
QualcommCq7790-
QualcommCq8725S Firmware-
QualcommCq8725S-
QualcommQca4024 Firmware-
QualcommQca4024-
QualcommQca6174A Firmware-
QualcommQca6174A-
QualcommQca8075 Firmware-
QualcommQca8075-
QualcommQca8080 Firmware-
QualcommQca8080-
QualcommQca8081 Firmware-
QualcommQca8081-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-25268?

CVE-2026-25268 is a vulnerability with a CVSS score of 8.8 (HIGH). Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.

How severe is CVE-2026-25268?

CVE-2026-25268 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2026-25268?

Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Wsa8835 Firmware, Qualcomm Wsa8835, Qualcomm 5G Fixed Wireless Access Platform Firmware, Qualcomm 5G Fixed Wireless Access Platform, Qualcomm Ar8035 Firmware.