CVE-2025-32459

HIGH
Published Jun 8, 2025 Modified Jan 21, 2026 CWE-88

Description

The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the sync_time argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.7 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This issue affects Quantenna Wi-Fi chipset through version 8.0.0.28 of the latest SDK, and appears to be unpatched at the time of this CVE record's first publishing, though the vendor has released a best practices guide for implementors of this chipset.

CVSS v3.1 Score

7.7
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weakness Type (CWE)

CWE-88 CWE-88

Affected Products

Vendor Product
onsemi qcs-ax3-s5_firmware
onsemi qcs-ax3-s5
onsemi qcs-ax2-a12_firmware
onsemi qcs-ax2-a12
onsemi qcs-ax2-t12_firmware
onsemi qcs-ax2-t12
onsemi qcs-ax2-t8_firmware
onsemi qcs-ax2-t8
onsemi qd840_firmware
onsemi qd840
onsemi qhs710_firmware
onsemi qhs710
onsemi qsr10ga_firmware
onsemi qsr10ga
onsemi qsr10gu_firmware
onsemi qsr10gu
onsemi qv840_firmware
onsemi qv840
onsemi qv840c_firmware
onsemi qv840c
onsemi qv860_firmware
onsemi qv860
onsemi qv940_firmware
onsemi qv940
onsemi qv942c_firmware
onsemi qv942c
onsemi qv952c_firmware
onsemi qv952c
onsemi qcs-ax2-s5_firmware
onsemi qcs-ax2-s5
onsemi qcs-ax3-a12_firmware
onsemi qcs-ax3-a12
onsemi qcs-ax3-t12_firmware
onsemi qcs-ax3-t12
onsemi qcs-ax3-t8_firmware
onsemi qcs-ax3-t8

References

Frequently Asked Questions

What is CVE-2025-32459? +
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the sync_time argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.7 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This issue affects Quantenna Wi-Fi chipset through version 8.0.0.28 of the latest SDK, and appears to be unpatched at the time of this CVE record's first publishing, though the vendor has released a best practices guide for implementors of this chipset. It has a CVSS v3.1 base score of 7.7 (HIGH).
How severe is CVE-2025-32459? +
CVE-2025-32459 has a CVSS v3.1 score of 7.7 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
What products are affected by CVE-2025-32459? +
CVE-2025-32459 affects products from onsemi, specifically: qcs-ax2-a12, qcs-ax2-a12_firmware, qcs-ax2-s5, qcs-ax2-s5_firmware, qcs-ax2-t12, qcs-ax2-t12_firmware, qcs-ax2-t8, qcs-ax2-t8_firmware, qcs-ax3-a12, qcs-ax3-a12_firmware, qcs-ax3-s5, qcs-ax3-s5_firmware, qcs-ax3-t12, qcs-ax3-t12_firmware, qcs-ax3-t8, qcs-ax3-t8_firmware, qd840, qd840_firmware, qhs710, qhs710_firmware, qsr10ga, qsr10ga_firmware, qsr10gu, qsr10gu_firmware, qv840, qv840_firmware, qv840c, qv840c_firmware, qv860, qv860_firmware, qv940, qv940_firmware, qv942c, qv942c_firmware, qv952c, qv952c_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2025-32459? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2025-32459 — free, no signup required.

Start Free Scan