Impact
The flaw is a buffer over‑read triggered when the WLAN firmware processes a Target Wake Time channel usage response frame that is shorter than expected. This can cause the device to crash, resulting in a temporary loss of Wi‑Fi connectivity. The weakness is classified as CWE‑126. Attackers that can transmit crafted frames to the device may be able to induce the over‑read and interrupt service availability.
Affected Systems
Qualcomm Snapdragon devices that run the affected WLAN firmware are impacted. Specific vendor and product names are Qualcomm, Inc.: Snapdragon; the affected firmware build identifiers are not listed, and no version range is supplied, so any device using the current firmware is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.4 indicates a high impact availability vulnerability. The EPSS score is not available, so the likelihood of exploitation is uncertain. The vulnerability is also not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote via a wireless link, requiring an attacker to send a malformed frame to a target device. If the vulnerability is exploited, the target would experience a short outage until the firmware is rebooted or patched.
OpenCVE Enrichment