CVE-2025-3460 Details
Description
The Quantenna Wi-Fi chipset ships with a local control script, set_tx_pow, that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.7 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This issue affects Quantenna Wi-Fi chipset through version 8.0.0.28 of the latest SDK, and appears to be unpatched at the time of this CVE record's first publishing, though the vendor has released a best practices guide for implementors of this chipset.
A command injection vulnerability has been identified in the Quantenna Wi-Fi chipset by ON Semiconductor, affecting chipsets through version 8.0.0.28 of the latest SDK. The vulnerability arises in a local control script called set_tx_pow, which lacks proper sanitization of input arguments, allowing arbitrary commands to be executed. This issue is present in various Quantenna Wi-Fi product families, including QT6300 AX3, QT62000 AX2, QSR10G and QSR5G AX, QSR1000 and QSR2000, and QHS710.
ON Semiconductor has published a best practices guide for securing products that use the Quantenna Wi-Fi chipset. This guide includes recommendations for disabling the qcsapi rpc service, changing default passwords, and configuring security options before production releases.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 9, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://community.onsemi.com/s/article/QCS-Quantenna-Wi-Fi-product-support-and-security-best-practices | [email protected] | Release Notes |
| https://takeonme.org/cves/cve-2025-3460 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-88 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| onsemi qcs-ax3-s5 firmware | All versions |
CPE
Remediation
| |
| onsemi qcs-ax3-s5 | All versions |
CPE
Remediation
| |
| onsemi qcs-ax2-a12 firmware | All versions |
CPE
Remediation
| |
| onsemi qcs-ax2-a12 | All versions |
CPE
Remediation
| |
| onsemi qcs-ax2-t12 firmware | All versions |
CPE
Remediation
| |
| onsemi qcs-ax2-t12 | All versions |
CPE
Remediation
| |
| onsemi qcs-ax2-t8 firmware | All versions |
CPE
Remediation
| |
| onsemi qcs-ax2-t8 | All versions |
CPE
Remediation
| |
| onsemi qd840 firmware | All versions |
CPE
Remediation
| |
| onsemi qd840 | All versions |
CPE
Remediation
| |
| onsemi qhs710 firmware | All versions |
CPE
Remediation
| |
| onsemi qhs710 | All versions |
CPE
Remediation
| |
| onsemi qsr10ga firmware | All versions |
CPE
Remediation
| |
| onsemi qsr10ga | All versions |
CPE
Remediation
| |
| onsemi qsr10gu firmware | All versions |
CPE
Remediation
| |
| onsemi qsr10gu | All versions |
CPE
Remediation
| |
| onsemi qv840 firmware | All versions |
CPE
Remediation
| |
| onsemi qv840 | All versions |
CPE
Remediation
| |
| onsemi qv840c firmware | All versions |
CPE
Remediation
| |
| onsemi qv840c | All versions |
CPE
Remediation
| |
| onsemi qv860 firmware | All versions |
CPE
Remediation
| |
| onsemi qv860 | All versions |
CPE
Remediation
| |
| onsemi qv940 firmware | All versions |
CPE
Remediation
| |
| onsemi qv940 | All versions |
CPE
Remediation
| |
| onsemi qv942c firmware | All versions |
CPE
Remediation
| |
| onsemi qv942c | All versions |
CPE
Remediation
| |
| onsemi qv952c firmware | All versions |
CPE
Remediation
| |
| onsemi qv952c | All versions |
CPE
Remediation
| |
| onsemi qcs-ax2-s5 firmware | All versions |
CPE
Remediation
| |
| onsemi qcs-ax2-s5 | All versions |
CPE
Remediation
| |
| onsemi qcs-ax3-a12 firmware | All versions |
CPE
Remediation
| |
| onsemi qcs-ax3-a12 | All versions |
CPE
Remediation
| |
| onsemi qcs-ax3-t12 firmware | All versions |
CPE
Remediation
| |
| onsemi qcs-ax3-t12 | All versions |
CPE
Remediation
| |
| onsemi qcs-ax3-t8 firmware | All versions |
CPE
Remediation
| |
| onsemi qcs-ax3-t8 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 21, 2026 | Initial Analysis | [email protected] |
| Jun 9, 2025 | CVE Modified | [email protected] |
| Jun 8, 2025 | New CVE Received | [email protected] |