CVE-2026-25262
CVE-2026-25262 is a medium-severity vulnerability in Qualcomm Mdm9207 Firmware with a CVSS 3.x base score of 6.9. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-123.
Key facts
- Severity: Medium (CVSS 3.x base score 6.9)
- EPSS exploit prediction: 0% (11th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-123
- Affected product: Qualcomm Mdm9207 Firmware
- Published:
- Last modified:
Description
Memory corruption while processing a crafted ELF file in the Primary Bootloader.
Frequently asked questions
- What is CVE-2026-25262?
- Memory corruption while processing a crafted ELF file in the Primary Bootloader.
- How severe is CVE-2026-25262?
- CVE-2026-25262 has a CVSS 3.x base score of 6.9, rated medium severity. It is exploitable over physical access with high attack complexity, requires low privileges and user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2026-25262 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (11th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-25262?
- CVE-2026-25262 primarily affects Qualcomm Mdm9207 Firmware. In total, 8 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2026-25262?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-25262 published?
- CVE-2026-25262 was published on 2026-09-22 and last updated on 2026-10-06.
References
Affected products (8)
- cpe:2.3:o:qualcomm:mdm9207_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:qualcomm:mdm9655_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:qualcomm:mdm9665_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:qualcomm:msm8909_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:qualcomm:msm8916_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:qualcomm:msm8952_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:qualcomm:sdx50_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:qualcomm:mdm9645_firmware:-:*:*:*:*:*:*:*
More vulnerabilities in Qualcomm Mdm9207 Firmware
- CVE-2022-40510 — Critical (CVSS 9.8): Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.
- CVE-2022-33259 — Critical (CVSS 9.8): Memory corruption due to buffer copy without checking the size of input in modem while decoding raw SMS received.
- CVE-2022-33211 — Critical (CVSS 9.8): memory corruption in modem due to improper check while calculating size of serialized CoAP message
- CVE-2022-25740 — Critical (CVSS 9.8): Memory corruption in modem due to buffer overwrite while building an IPv6 multicast address based on the MAC address of…
- CVE-2022-25678 — Critical (CVSS 9.8): Memory correction in modem due to buffer overwrite during coap connection
- CVE-2022-25727 — Critical (CVSS 9.8): Memory Corruption in modem due to improper length check while copying into memory in Snapdragon Consumer IOT,…
All CVEs affecting Qualcomm Mdm9207 Firmware →
Other CWE-123 vulnerabilities
- CVE-2025-69809 — Critical (CVSS 9.8): A write-what-where condition in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to write arbitrary values…
- CVE-2022-38143 — Critical (CVSS 9.8): A heap out-of-bounds write vulnerability exists in the way OpenImageIO v2.3.19.0 processes RLE encoded BMP images. A…
- CVE-2021-38449 — Critical (CVSS 9.8): Some API functions permit by-design writing or copying data into a given buffer. Since the client controls these…
- CVE-2015-8271 — Critical (CVSS 9.8): The AMF3CD_AddProp function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to execute arbitrary code.
- CVE-2026-30121 — Critical (CVSS 9.1): remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability.
- CVE-2026-81579 — High (CVSS 8.8): In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for…