← Vulnerability feed

Vulnerability record · CVE-2025-47400 · published 6 April 2026

CVE-2025-47400: Qualcomm pandeiro firmware vulnerability

Qualcomm · Pandeiro Firmware

Cryptographic issue while copying data to a destination buffer without validating its size.

7.1 CVSS 3.1 High EPSS 0.10% · top 99.4% CWE-126 · CWE-126
7.1CVSS 3.1 base score
0.10%EPSS exploitation probability, 30 days
NoNot in CISA KEV
11Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Cryptographic issue while copying data to a destination buffer without validating its size.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected products

11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-47400 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2026-21385Qualcomm chipset firmware memory corruption via alignment integer overflowA memory corruption flaw in Qualcomm chipset firmware arises from an integer overflow when alignments are used for memory allocation (CWE-190). It af…KEVEPSS 1.2%analysed9.6CVE-2026-25289Qualcomm sm7550p firmware stack-based buffer overflow vulnerabilityMemory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.EPSS 0.19%8.8CVE-2026-25276Qualcomm cq8750m firmware vulnerabilityMemory corruption while using Strongbox due to missing bounds check.EPSS 0.08%8.8CVE-2026-25277Qualcomm cq8750m firmware classic buffer overflow vulnerabilityMemory corruption while using Strongbox due to buffer overflow.EPSS 0.07%8.8CVE-2025-47392Qualcomm 5g fixed wireless access platform firmware integer overflow vulnerabilityMemory corruption when decoding corrupted satellite data files with invalid signature offsets.EPSS 0.17%8.2CVE-2026-24088Qualcomm ar9380 firmware missing authentication for critical function vulnerabilityCryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.EPSS 0.07%8.1CVE-2026-24079Qualcomm ar8035 firmware missing authentication for critical function vulnerabilityCryptographic Issue while processing registration requests with malformed or missing authentication parameters.EPSS 0.21%7.8CVE-2026-24080Qualcomm qam8295p firmware classic buffer overflow vulnerabilityMemory Corruption when handling malformed request parameters in the fingerprint TA.EPSS 0.10%

Source: NIST National Vulnerability Database (record CVE-2025-47400), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.