PT-2025-24371 · Quantenna · Quantenna Wi-Fi Chipset

·

CVE-2025-32458

·

Published

2025-03-27

·

Updated

2026-01-21

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Quantenna Wi-Fi chipset versions through 8.0.0.28
Description The Quantenna Wi-Fi chipset has a local control script, router command.sh, that is vulnerable to command injection, specifically in the get syslog from qtn argument. This issue is related to improper neutralization of argument delimiters in a command. The vendor has released a best practices guide for implementors of this chipset.
Recommendations For versions through 8.0.0.28, consider disabling the router command.sh script or restricting its use until a patch is available. Implement the best practices guide provided by the vendor to minimize the risk of exploitation.

Fix

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06627
CVE-2025-32458

Affected Products

Quantenna Wi-Fi Chipset