Description
Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
Published: 2026-08-04
Score: 7.4 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a buffer over‑read triggered when the WLAN firmware processes a Target Wake Time channel usage response frame that is shorter than expected. This can cause the device to crash, resulting in a temporary loss of Wi‑Fi connectivity. The weakness is classified as CWE‑126. Attackers that can transmit crafted frames to the device may be able to induce the over‑read and interrupt service availability.

Affected Systems

Qualcomm Snapdragon devices that run the affected WLAN firmware are impacted. Specific vendor and product names are Qualcomm, Inc.: Snapdragon; the affected firmware build identifiers are not listed, and no version range is supplied, so any device using the current firmware is potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.4 indicates a high impact availability vulnerability. The EPSS score is not available, so the likelihood of exploitation is uncertain. The vulnerability is also not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote via a wireless link, requiring an attacker to send a malformed frame to a target device. If the vulnerability is exploited, the target would experience a short outage until the firmware is rebooted or patched.

Generated by OpenCVE AI on August 4, 2026 at 19:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Qualcomm Snapdragon WLAN firmware update that addresses the buffer over‑read.
  • If product configuration allows, restrict or disable reception of Target Wake Time channel usage response frames on the device.
  • Monitor device logs for abnormal packet drops or crashes and report incidents to Qualcomm support while awaiting a definitive patch.

Generated by OpenCVE AI on August 4, 2026 at 19:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
Title Buffer Over-read in WLAN Firmware
Weaknesses CWE-126
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-08-04T15:47:13.946Z

Reserved: 2026-02-02T04:19:00.942Z

Link: CVE-2026-25288

cve-icon Vulnrichment

Updated: 2026-08-04T15:47:10.460Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T19:45:03Z

Weaknesses