Impact
The flaw is a buffer over-read that can be triggered when the WLAN firmware parses a frame while the device is actively using a channel. The over-read can cause the firmware to crash or reset, resulting in a temporary loss of connectivity. The impact is limited to availability; no evidence indicates that the vulnerability permits code execution, privilege escalation, or data disclosure.
Affected Systems
Qualcomm, Inc. Snapdragon WLAN firmware devices are affected. No specific firmware versions are listed, so all Snapdragon WLAN implementations that include the vulnerable parsing routine are potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.4 indicates a moderate to high severity. The EPSS score of less than 1% suggests that exploitation is unlikely at present, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a remote network attacker who can transmit a specially crafted WLAN frame to the device; however, this is inferred rather than explicitly stated in the data.
OpenCVE Enrichment