The SentinelOne Annual Threat Report - A Defenders Guide from the FrontlinesThe SentinelOne Annual Threat ReportGet the Report
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2025-47328

CVE-2025-47328: Qualcomm Fastconnect 7800 DOS Vulnerability

CVE-2025-47328 is a denial of service vulnerability in Qualcomm Fastconnect 7800 Firmware caused by processing power control requests with invalid antenna or stream values. This article covers technical details, impact, and mitigation.

Published: April 22, 2026

CVE-2025-47328 Overview

CVE-2025-47328 is a transient denial of service vulnerability affecting Qualcomm firmware across a wide range of networking and wireless chipsets. The vulnerability occurs during the processing of power control requests when invalid antenna or stream values are provided, resulting in a buffer over-read condition (CWE-126). This flaw allows remote attackers to cause a temporary service disruption without requiring authentication or user interaction.

Critical Impact

Remote attackers can exploit this vulnerability to cause transient denial of service conditions on affected Qualcomm wireless and networking devices, potentially disrupting connectivity for enterprise and consumer systems.

Affected Products

  • Qualcomm FastConnect 7800 Firmware
  • Qualcomm IPQ Series (IPQ5300, IPQ5302, IPQ5312, IPQ5332, IPQ5424, IPQ9008, IPQ9048, IPQ9554, IPQ9570, IPQ9574)
  • Qualcomm QCN Series (QCN5124, QCN5224, QCN6224, QCN6274, QCN6402, QCN6412, QCN6422, QCN6432, QCN9000, QCN9012, QCN9024, QCN9074, QCN9160, QCN9274)
  • Qualcomm Snapdragon X72 and X75 5G Modem-RF Systems
  • Qualcomm Immersive Home 3210 and 326 Platforms
  • Qualcomm WCN Series (WCN7750, WCN7860, WCN7861, WCN7880, WCN7881)
  • Qualcomm QCA Series (QCA0000, QCA8075-QCA8386)
  • Qualcomm SM8735, SM8750, SM8750P Firmware
  • Qualcomm WCD and WSA Audio Codec Firmware

Discovery Timeline

  • September 24, 2025 - CVE-2025-47328 published to NVD
  • September 25, 2025 - Last updated in NVD database

Technical Details for CVE-2025-47328

Vulnerability Analysis

The vulnerability exists in the power control request handling mechanism within affected Qualcomm firmware. When processing power control requests, the firmware fails to properly validate antenna or stream parameter values before using them to access memory buffers. This creates a buffer over-read condition where the firmware may read beyond the allocated memory boundaries.

The attack can be initiated remotely over a network connection without requiring any authentication credentials or user interaction. The vulnerability specifically impacts availability, causing a transient denial of service condition. No confidentiality or integrity impacts have been identified, meaning the vulnerability cannot be used to exfiltrate data or modify system configurations.

The transient nature of this DoS means affected devices may recover automatically after the attack ceases, but repeated exploitation could cause persistent service disruptions affecting wireless connectivity and network operations.

Root Cause

The root cause is a buffer over-read vulnerability (CWE-126) stemming from insufficient validation of input parameters. When the firmware receives power control requests containing out-of-bounds antenna or stream index values, it fails to verify these values fall within expected ranges before using them as array indices or buffer offsets. This allows an attacker to trigger reads from memory locations outside the intended buffer boundaries.

Attack Vector

The attack vector is network-based, requiring no privileges and no user interaction. An attacker can craft malicious power control requests containing invalid antenna or stream values and send them to vulnerable devices over the network.

The exploitation flow involves:

  1. An attacker identifies a device running vulnerable Qualcomm firmware
  2. The attacker crafts a power control request with malformed antenna or stream parameters containing values outside valid ranges
  3. The malicious request is transmitted to the target device over the network
  4. The firmware processes the request without proper bounds checking
  5. A buffer over-read occurs, causing the device to enter a denial of service state

Due to the lack of public exploit code and the transient nature of the DoS condition, this vulnerability presents a moderate but manageable risk when properly mitigated.

Detection Methods for CVE-2025-47328

Indicators of Compromise

  • Unexpected device reboots or wireless connectivity interruptions on systems using affected Qualcomm chipsets
  • Network traffic containing anomalous power control requests with out-of-range parameter values
  • Firmware crash logs indicating buffer over-read errors in power control processing routines
  • Repeated transient service disruptions affecting Qualcomm-based networking equipment

Detection Strategies

  • Monitor network traffic for malformed power control frames targeting Qualcomm wireless interfaces
  • Implement firmware crash analysis to identify patterns consistent with buffer over-read exploitation
  • Deploy network intrusion detection rules to flag power control requests with invalid antenna or stream values
  • Review system logs on affected devices for unexpected restart events or error conditions

Monitoring Recommendations

  • Enable verbose logging on enterprise wireless access points and routers using affected Qualcomm chipsets
  • Implement network traffic analysis at network boundaries to detect potential exploitation attempts
  • Configure alerting for unusual patterns of wireless connectivity disruptions
  • Monitor device health metrics for affected Qualcomm-based systems to detect transient DoS conditions

How to Mitigate CVE-2025-47328

Immediate Actions Required

  • Review the Qualcomm Security Bulletin September 2025 for complete vulnerability details
  • Inventory all devices using affected Qualcomm chipsets and firmware versions in your environment
  • Prioritize firmware updates for internet-facing and critical infrastructure devices
  • Implement network segmentation to limit exposure of vulnerable devices until patches can be applied

Patch Information

Qualcomm has published security information regarding this vulnerability in their September 2025 Security Bulletin. Organizations should obtain updated firmware from their device vendors who incorporate affected Qualcomm chipsets. The following resources provide official guidance:

  • Qualcomm Security Bulletin September 2025 - Official vendor advisory with patch information

Contact your device manufacturer (OEM) for specific firmware update packages, as Qualcomm chipset firmware is typically distributed through device vendors rather than directly from Qualcomm.

Workarounds

  • Implement network access controls to restrict which systems can send power control requests to vulnerable devices
  • Deploy network filtering at perimeter devices to block malformed wireless management traffic
  • Consider isolating critical Qualcomm-based devices on separate network segments with strict access policies
  • Monitor for unusual traffic patterns targeting wireless management interfaces until patches are deployed
bash
# Example: Network segmentation configuration for isolating vulnerable IoT/wireless devices
# Apply appropriate firewall rules based on your network architecture

# Restrict management interface access to trusted networks only
iptables -A INPUT -p udp --dport 5246 -s 10.0.0.0/8 -j ACCEPT
iptables -A INPUT -p udp --dport 5246 -j DROP

# Log suspicious traffic patterns for analysis
iptables -A INPUT -p udp --dport 5246 -j LOG --log-prefix "CAPWAP_CONTROL: "

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeDOS

  • Vendor/TechQualcomm

  • SeverityHIGH

  • CVSS Score7.5

  • EPSS Probability0.06%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-126
  • Vendor Resources
  • Qualcomm Security Bulletin September 2025
  • Related CVEs
  • CVE-2025-47401: Qualcomm Fastconnect 6200 DOS Vulnerability

  • CVE-2025-47403: Snapdragon X65 5G Modem DOS Vulnerability

  • CVE-2026-21367: Qualcomm AR8035 Firmware DOS Vulnerability

  • CVE-2026-21381: Qualcomm AR8035 Firmware DOS Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the World’s Most Advanced Cybersecurity Platform

See how our intelligent, autonomous cybersecurity platform can protect your organization now and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English