CVE-2025-32456
HIGHDescription
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the put_file_to_qtn argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.7 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This issue affects Quantenna Wi-Fi chipset through version 8.0.0.28 of the latest SDK, and appears to be unpatched at the time of this CVE record's first publishing, though the vendor has released a best practices guide for implementors of this chipset.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| onsemi | qcs-ax3-s5_firmware |
| onsemi | qcs-ax3-s5 |
| onsemi | qcs-ax2-a12_firmware |
| onsemi | qcs-ax2-a12 |
| onsemi | qcs-ax2-t12_firmware |
| onsemi | qcs-ax2-t12 |
| onsemi | qcs-ax2-t8_firmware |
| onsemi | qcs-ax2-t8 |
| onsemi | qd840_firmware |
| onsemi | qd840 |
| onsemi | qhs710_firmware |
| onsemi | qhs710 |
| onsemi | qsr10ga_firmware |
| onsemi | qsr10ga |
| onsemi | qsr10gu_firmware |
| onsemi | qsr10gu |
| onsemi | qv840_firmware |
| onsemi | qv840 |
| onsemi | qv840c_firmware |
| onsemi | qv840c |
| onsemi | qv860_firmware |
| onsemi | qv860 |
| onsemi | qv940_firmware |
| onsemi | qv940 |
| onsemi | qv942c_firmware |
| onsemi | qv942c |
| onsemi | qv952c_firmware |
| onsemi | qv952c |
| onsemi | qcs-ax2-s5_firmware |
| onsemi | qcs-ax2-s5 |
| onsemi | qcs-ax3-a12_firmware |
| onsemi | qcs-ax3-a12 |
| onsemi | qcs-ax3-t12_firmware |
| onsemi | qcs-ax3-t12 |
| onsemi | qcs-ax3-t8_firmware |
| onsemi | qcs-ax3-t8 |
References
Frequently Asked Questions
What is CVE-2025-32456? +
How severe is CVE-2025-32456? +
What products are affected by CVE-2025-32456? +
How do I check if I'm vulnerable to CVE-2025-32456? +
Related Vulnerabilities
A hidden console command is vulnerable to command injection flaw when control characters are passed to its second argument. A …
Atheos is a self-hosted browser-based cloud integrated development environment. Prior to version 6.0.4, improper use of `escapeshellcmd()` in `/components/codegit/traits/execute.php` allows …
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations …
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in CRESTRON TOUCHSCREENS x70 allows Argument Injection.This issue affects …
XZ Utils provide a general-purpose data-compression library plus command-line tools. When built for native Windows (MinGW-w64 or MSVC), the command …
Easywall 0.3.1 allows authenticated remote command execution via a command injection vulnerability in the /ports-save endpoint that suffers from a …