← Vulnerability feed

Vulnerability record · CVE-2025-47395 · published 7 January 2026

CVE-2025-47395: Qualcomm wcn7861 firmware vulnerability

Qualcomm · Wcn7861 Firmware

Transient DOS while parsing a WLAN management frame with a Vendor Specific Information Element.

6.5 CVSS 3.1 Medium EPSS 0.11% · top 98.6% CWE-126 · CWE-126
6.5CVSS 3.1 base score
0.11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Transient DOS while parsing a WLAN management frame with a Vendor Specific Information Element.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-47395 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2025-21479Qualcomm GPU micronode memory corruption via unauthorized command executionQualcomm chipsets contain an incorrect authorization flaw in the GPU micronode that allows memory corruption when a specific sequence of commands is …KEVEPSS 0.84%analysed8.6CVE-2025-21480Qualcomm GPU micronode memory corruption via unauthorized command executionA memory corruption flaw in Qualcomm's GPU micronode is caused by incorrect authorization (CWE-863), allowing an unauthorized command sequence to be …KEVEPSS 0.46%analysed9.8CVE-2025-27034Qualcomm fastconnect 6900 firmware vulnerabilityMemory corruption while selecting the PLMN from SOR failed list.EPSS 0.40%9.8CVE-2025-21483Qualcomm apq8017 firmware memory buffer overflow vulnerabilityMemory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.EPSS 0.40%9.6CVE-2026-25289Qualcomm sm7550p firmware stack-based buffer overflow vulnerabilityMemory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.EPSS 0.19%9.1CVE-2025-21450Qualcomm ar8035 firmware improper authentication vulnerabilityCryptographic issue occurs due to use of insecure connection method while downloading.EPSS 0.31%9.1CVE-2024-38408Qualcomm wsa8845h firmware vulnerabilityCryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.EPSS 0.15%8.8CVE-2026-25268Qualcomm wsa8835 firmware stack-based buffer overflow vulnerabilityMemory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.EPSS 0.11%

Source: NIST National Vulnerability Database (record CVE-2025-47395), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.