CVE-2025-21426

Memory corruption while processing camera TPG write request.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:qualcomm:fastconnect_7800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_7800:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:qualcomm:snapdragon_ar1_gen_1_platform_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_ar1_gen_1_platform:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:qualcomm:ssg2115p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:ssg2115p:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:qualcomm:ssg2125p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:ssg2125p:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:qualcomm:sxr1230p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sxr1230p:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:qualcomm:wcd9380_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9380:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:qualcomm:wcd9385_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9385:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:qualcomm:wsa8830_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8830:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:qualcomm:wsa8832_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8832:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:qualcomm:wsa8835_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8835:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-07-08 13:15

Updated : 2025-07-21 19:37


NVD link : CVE-2025-21426

Mitre link : CVE-2025-21426

CVE.ORG link : CVE-2025-21426


JSON object : View

Products Affected

qualcomm

  • wsa8832
  • ssg2115p_firmware
  • fastconnect_7800_firmware
  • ssg2125p
  • wsa8835
  • ssg2115p
  • snapdragon_ar1_gen_1_platform_firmware
  • ssg2125p_firmware
  • wsa8830
  • wcd9380_firmware
  • wsa8830_firmware
  • wcd9380
  • snapdragon_ar1_gen_1_platform
  • fastconnect_7800
  • wsa8835_firmware
  • sxr1230p_firmware
  • wcd9385
  • wsa8832_firmware
  • wcd9385_firmware
  • sxr1230p
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')