Impact
The discovered flaw is a buffer over‑read in Qualcomm Snapdragon WLAN firmware that occurs while processing authentication frames containing an invalid FILS information element header length. When the firmware reads past the end of the supplied header, the device can crash, resulting in a transient denial of service that disconnects the wireless network without exposing any disclosure or code execution vectors.
Affected Systems
Qualcomm, Inc. Snapdragon firmware is affected. No specific firmware revision or patch level is listed, so all versions that include the current FILS processing logic are potentially vulnerable.
Risk and Exploitability
The vulnerability receives a CVSS score of 7.5, placing it in the high‑severity range. The EPSS score of less than 1% indicates a very low probability of exploitation in the general threat landscape, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote wireless attacker who can inject malformed authentication frames into the device’s traffic stream. A successful exploitation would trigger the firmware crash, temporarily disabling WLAN connectivity but would not grant persistent access or data leakage.
OpenCVE Enrichment