← Vulnerability feed

Vulnerability record · CVE-2026-25294 · published 17 September 2026

CVE-2026-25294: Qualcomm cologne firmware vulnerability

Qualcomm · Cologne Firmware

Transient DOS while parsing frame during channel usage.

7.4 CVSS 3.1 High EPSS 0.10% · top 99.2% CWE-126 · CWE-126
7.4CVSS 3.1 base score
0.10%EPSS exploitation probability, 30 days
NoNot in CISA KEV
75Affected product versions listed by NVD
1References
22 Sep 2026Last modified by NVD

Description

Transient DOS while parsing frame during channel usage.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Affected products

75 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-25294 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.6CVE-2026-25289Qualcomm sm7550p firmware stack-based buffer overflow vulnerabilityMemory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.EPSS 0.19%8.8CVE-2026-25283Qualcomm cologne firmware stack-based buffer overflow vulnerabilityMemory Corruption when copying unverified data from an external source exceeds the allocated buffer size.EPSS 0.07%8.8CVE-2026-25268Qualcomm wsa8835 firmware stack-based buffer overflow vulnerabilityMemory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.EPSS 0.11%7.9CVE-2026-25282Qualcomm cologne firmware out-of-bounds read vulnerabilityTransient DOS when processing unverified data from a neighboring system causes out of bound memory access.EPSS 0.06%7.8CVE-2026-25290Qualcomm cologne firmware integer overflow vulnerabilityMemory Corruption when validating large data buffers from external sources using addition to check buffer length.EPSS 0.07%7.8CVE-2026-25261Qualcomm cologne firmware vulnerabilityMemory corruption while processing rear sensor IOCTL calls.EPSS 0.07%7.8CVE-2026-25280Qualcomm wsa8845h firmware out-of-bounds write vulnerabilityMemory corruption when processing escape handling flow with insufficient user buffer sizes.EPSS 0.07%7.8CVE-2026-24073Qualcomm cologne firmware out-of-bounds write vulnerabilityMemory corruption when processing decode statistics due to insufficient validation of offset against structure size.EPSS 0.07%

Source: NIST National Vulnerability Database (record CVE-2026-25294), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.