Description
Cryptographic issue while copying data to a destination buffer without validating its size.
Published: 2026-04-06
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch Now
AI Analysis

Impact

The flaw is a buffer over‑read that occurs when Qualcomm’s computer vision component copies cryptographic data to a destination buffer without first checking the buffer size. This omission can allow an attacker to read beyond the intended memory region, potentially exposing secret data such as cryptographic keys or other sensitive information. The weakness is commonly known as buffer over-read (CWE‑126).

Affected Systems

The vulnerability affects Qualcomm’s Snapdragon line, including devices such as the Snapdragon 8 Elite Gen 5, Pandeiro, SW6100, SW6100P, Themisto, WCD9395, WCN7860, WCN7861, WSA8840, WSA8845, and WSA8845H, as well as the corresponding firmware editions. These components are listed in the Qualcomm security bulletin and may be susceptible if they have not been updated to the fixed revision. Exact affected firmware releases are not included in the available data, so any hardware running the affected firmware stack is potentially impacted.

Risk and Exploitability

The CVSS base score of 7.1 indicates a high severity risk, while an EPSS score of less than 1% suggests that exploitation is unlikely to be widespread in the near future. The vulnerability is not listed in CISA’s KEV catalog, implying no known large‑scale exploitation. Likely attackers would require local or privileged access to the device, as the over‑read occurs within an internal cryptographic routine rather than through a network interface. Consequently, organizations can assess the risk based on their exposure model, but keeping firmware current is advised.

Generated by OpenCVE AI on April 8, 2026 at 23:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Qualcomm firmware or software updates as documented in the April 2026 security bulletin.
  • Verify that your device firmware matches the fixed version mentioned in the bulletin.
  • If an update is unavailable for your device, disable or limit the computer‑vision or cryptographic features that trigger the vulnerability.
  • Monitor system logs for anomalous memory access or read errors that could indicate exploitation attempts.

Generated by OpenCVE AI on April 8, 2026 at 23:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Apr 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm pandeiro
Qualcomm pandeiro Firmware
Qualcomm snapdragon 8 Elite Gen 5
Qualcomm snapdragon 8 Elite Gen 5 Firmware
Qualcomm sw6100
Qualcomm sw6100 Firmware
Qualcomm sw6100p
Qualcomm sw6100p Firmware
Qualcomm themisto
Qualcomm themisto Firmware
Qualcomm wcd9395
Qualcomm wcd9395 Firmware
Qualcomm wcn7860
Qualcomm wcn7860 Firmware
Qualcomm wcn7861
Qualcomm wcn7861 Firmware
Qualcomm wsa8840
Qualcomm wsa8840 Firmware
Qualcomm wsa8845
Qualcomm wsa8845 Firmware
Qualcomm wsa8845h
Qualcomm wsa8845h Firmware
CPEs cpe:2.3:h:qualcomm:pandeiro:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_8_elite_gen_5:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sw6100:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sw6100p:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:themisto:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9395:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn7860:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn7861:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8840:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845h:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:pandeiro_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_8_elite_gen_5_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sw6100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sw6100p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:themisto_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9395_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcn7860_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcn7861_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8840_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845h_firmware:-:*:*:*:*:*:*:*
Vendors & Products Qualcomm pandeiro
Qualcomm pandeiro Firmware
Qualcomm snapdragon 8 Elite Gen 5
Qualcomm snapdragon 8 Elite Gen 5 Firmware
Qualcomm sw6100
Qualcomm sw6100 Firmware
Qualcomm sw6100p
Qualcomm sw6100p Firmware
Qualcomm themisto
Qualcomm themisto Firmware
Qualcomm wcd9395
Qualcomm wcd9395 Firmware
Qualcomm wcn7860
Qualcomm wcn7860 Firmware
Qualcomm wcn7861
Qualcomm wcn7861 Firmware
Qualcomm wsa8840
Qualcomm wsa8840 Firmware
Qualcomm wsa8845
Qualcomm wsa8845 Firmware
Qualcomm wsa8845h
Qualcomm wsa8845h Firmware

Tue, 07 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm
Qualcomm snapdragon
Vendors & Products Qualcomm
Qualcomm snapdragon

Mon, 06 Apr 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Apr 2026 16:45:00 +0000

Type Values Removed Values Added
Description Cryptographic issue while copying data to a destination buffer without validating its size.
Title Buffer Over-read in Computer Vision
Weaknesses CWE-126
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Qualcomm Pandeiro Pandeiro Firmware Snapdragon Snapdragon 8 Elite Gen 5 Snapdragon 8 Elite Gen 5 Firmware Sw6100 Sw6100 Firmware Sw6100p Sw6100p Firmware Themisto Themisto Firmware Wcd9395 Wcd9395 Firmware Wcn7860 Wcn7860 Firmware Wcn7861 Wcn7861 Firmware Wsa8840 Wsa8840 Firmware Wsa8845 Wsa8845 Firmware Wsa8845h Wsa8845h Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-04-07T03:55:46.892Z

Reserved: 2025-05-06T08:33:16.276Z

Link: CVE-2025-47400

cve-icon Vulnrichment

Updated: 2026-04-06T16:21:43.446Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-06T16:16:28.590

Modified: 2026-04-08T21:05:12.693

Link: CVE-2025-47400

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-09T08:28:57Z

Weaknesses