CVE-2025-27065
📋 TL;DR
This vulnerability allows an attacker to cause a Denial of Service (DoS) by sending a specially crafted frame with a malformed shared-key descriptor to affected Qualcomm wireless components. The attack disrupts normal processing, potentially causing system instability or crashes. This affects devices using vulnerable Qualcomm wireless chipsets.
💻 Affected Systems
- Qualcomm wireless chipsets and associated firmware
📦 What is this software?
Immersive Home 3210 Platform Firmware by Qualcomm
View all CVEs affecting Immersive Home 3210 Platform Firmware →
Immersive Home 326 Platform Firmware by Qualcomm
View all CVEs affecting Immersive Home 326 Platform Firmware →
Snapdragon 8 Gen 1 Mobile Platform Firmware by Qualcomm
View all CVEs affecting Snapdragon 8 Gen 1 Mobile Platform Firmware →
Snapdragon 8 Gen 2 Mobile Platform Firmware by Qualcomm
View all CVEs affecting Snapdragon 8 Gen 2 Mobile Platform Firmware →
Snapdragon 8 Gen 2 Mobile Platform Firmware by Qualcomm
View all CVEs affecting Snapdragon 8 Gen 2 Mobile Platform Firmware →
Snapdragon 8 Gen 3 Mobile Platform Firmware by Qualcomm
View all CVEs affecting Snapdragon 8 Gen 3 Mobile Platform Firmware →
Snapdragon 865 5g Mobile Platform Firmware by Qualcomm
View all CVEs affecting Snapdragon 865 5g Mobile Platform Firmware →
Snapdragon 865\+ 5g Mobile Platform \(sm8250 Ab\) Firmware by Qualcomm
View all CVEs affecting Snapdragon 865\+ 5g Mobile Platform \(sm8250 Ab\) Firmware →
Snapdragon 870 5g Mobile Platform \(sm8250 Ac\) Firmware by Qualcomm
View all CVEs affecting Snapdragon 870 5g Mobile Platform \(sm8250 Ac\) Firmware →
Snapdragon Ar1 Gen 1 Platform \"luna1\" Firmware by Qualcomm
View all CVEs affecting Snapdragon Ar1 Gen 1 Platform \"luna1\" Firmware →
Snapdragon Ar1 Gen 1 Platform Firmware by Qualcomm
View all CVEs affecting Snapdragon Ar1 Gen 1 Platform Firmware →
Snapdragon Ar2 Gen 1 Platform Firmware by Qualcomm
View all CVEs affecting Snapdragon Ar2 Gen 1 Platform Firmware →
Snapdragon Auto 5g Modem Rf Gen 2 Firmware by Qualcomm
View all CVEs affecting Snapdragon Auto 5g Modem Rf Gen 2 Firmware →
Snapdragon X72 5g Modem Rf System Firmware by Qualcomm
View all CVEs affecting Snapdragon X72 5g Modem Rf System Firmware →
Snapdragon X75 5g Modem Rf System Firmware by Qualcomm
View all CVEs affecting Snapdragon X75 5g Modem Rf System Firmware →
⚠️ Risk & Real-World Impact
Worst Case
Complete system crash requiring reboot, disrupting all wireless connectivity and potentially affecting device stability.
Likely Case
Temporary service disruption affecting wireless connectivity until system recovers or reboots.
If Mitigated
Minimal impact with proper network segmentation and monitoring; system may experience brief performance degradation.
🎯 Exploit Status
Exploitation requires crafting and sending specific malformed frames to wireless interfaces; no authentication needed but requires network access to target.
🛠️ Fix & Mitigation
✅ Official Fix
Patch Version: Patched versions detailed in August 2025 Qualcomm security bulletin
Vendor Advisory: https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2025-bulletin.html
Restart Required: Yes
Instructions:
1. Check Qualcomm advisory for specific affected products. 2. Obtain updated firmware from device manufacturer. 3. Apply firmware update following manufacturer instructions. 4. Reboot device to activate patched firmware.
🔧 Temporary Workarounds
Network Segmentation
allIsolate wireless networks from critical infrastructure to limit attack surface.
Wireless Access Control
allImplement strict wireless authentication and MAC filtering to limit who can send frames.
🧯 If You Can't Patch
- Monitor wireless interfaces for unusual frame patterns or DoS attempts.
- Implement network-based intrusion detection to alert on malformed frame attacks.
🔍 How to Verify
Check if Vulnerable:
Check device firmware version against Qualcomm's advisory; use manufacturer-specific commands to query wireless chipset firmware.
Check Version:
Manufacturer-specific; typically 'adb shell getprop ro.build.fingerprint' for Android or system-specific firmware query commands.
Verify Fix Applied:
Verify firmware version matches patched version from Qualcomm advisory after update.
📡 Detection & Monitoring
Log Indicators:
- Wireless driver crashes
- Kernel panic logs related to wireless modules
- Increased error rates on wireless interfaces
Network Indicators:
- Unusual spike in malformed wireless frames
- Specific frame patterns matching shared-key descriptor anomalies
SIEM Query:
Wireless logs showing driver crashes OR kernel panics with wireless module references