PT-2025-28439 · Qualcomm · Qualcomm Chipsets

Published

2025-01-06

·

Updated

2025-07-21

·

CVE-2025-21450

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Qualcomm chipsets versions prior to the fixed version
Description: A cryptographic issue occurs due to the use of an insecure connection method while downloading. This issue affects over 100 Qualcomm chipsets used in many Android devices.
Recommendations: For Qualcomm chipsets versions prior to the fixed version, update to a version that includes a fix for the cryptographic issue as soon as it becomes available. As a temporary workaround, consider restricting the use of insecure connection methods to minimize the risk of exploitation.

Fix

Incorrect Authorization

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2025-10999
CVE-2025-21450

Affected Products

Qualcomm Chipsets