CVE-2025-21457 Details
Description
Information disclosure while opening a fastrpc session when domain is not sanitized.
A buffer over-read vulnerability has been identified in Qualcomm's Automotive Android OS platform. This vulnerability allows for information disclosure when a fastrpc session is opened without proper domain sanitization. The issue affects several chipsets, including those used in various Snapdragon 5G mobile platforms and automotive applications.
Qualcomm has released patches for this vulnerability. Instructions for applying the patch can be found in the Qualcomm August 2025 Security Bulletin.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2025-bulletin.html | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-126 | Buffer Over-read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| qualcomm ar8035 firmware | All versions |
CPE
Remediation
| |
| qualcomm ar8035 | All versions |
CPE
Remediation
| |
| qualcomm fastconnect 7800 firmware | All versions |
CPE
Remediation
| |
| qualcomm fastconnect 7800 | All versions |
CPE
Remediation
| |
| qualcomm qca6584au firmware | All versions |
CPE
Remediation
| |
| qualcomm qca6584au | All versions |
CPE
Remediation
| |
| qualcomm qca6698aq firmware | All versions |
CPE
Remediation
| |
| qualcomm qca6698aq | All versions |
CPE
Remediation
| |
| qualcomm qca8081 firmware | All versions |
CPE
Remediation
| |
| qualcomm qca8081 | All versions |
CPE
Remediation
| |
| qualcomm qca8337 firmware | All versions |
CPE
Remediation
| |
| qualcomm qca8337 | All versions |
CPE
Remediation
| |
| qualcomm qcc710 firmware | All versions |
CPE
Remediation
| |
| qualcomm qcc710 | All versions |
CPE
Remediation
| |
| qualcomm qcn6224 firmware | All versions |
CPE
Remediation
| |
| qualcomm qcn6224 | All versions |
CPE
Remediation
| |
| qualcomm qcn6274 firmware | All versions |
CPE
Remediation
| |
| qualcomm qcn6274 | All versions |
CPE
Remediation
| |
| qualcomm qfw7114 firmware | All versions |
CPE
Remediation
| |
| qualcomm qfw7114 | All versions |
CPE
Remediation
| |
| qualcomm qfw7124 firmware | All versions |
CPE
Remediation
| |
| qualcomm qfw7124 | All versions |
CPE
Remediation
| |
| qualcomm snapdragon auto 5g modem-rf gen 2 firmware | All versions |
CPE
Remediation
| |
| qualcomm snapdragon auto 5g modem-rf gen 2 | All versions |
CPE
Remediation
| |
| qualcomm snapdragon x72 5g modem-rf system firmware | All versions |
CPE
Remediation
| |
| qualcomm snapdragon x72 5g modem-rf system | All versions |
CPE
Remediation
| |
| qualcomm snapdragon x75 5g modem-rf system firmware | All versions |
CPE
Remediation
| |
| qualcomm snapdragon x75 5g modem-rf system | All versions |
CPE
Remediation
| |
| qualcomm wcd9340 firmware | All versions |
CPE
Remediation
| |
| qualcomm wcd9340 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 19, 2025 | Initial Analysis | [email protected] |
| Aug 6, 2025 | New CVE Received | [email protected] |