CVE-2026-25266
MEDIUMDescription
Memory corruption while processing IOCTL command when device is in power-save state.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| qualcomm | cologne_firmware |
| qualcomm | cologne |
| qualcomm | fastconnect_6900_firmware |
| qualcomm | fastconnect_6900 |
| qualcomm | fastconnect_7800_firmware |
| qualcomm | fastconnect_7800 |
| qualcomm | sc8380xp_firmware |
| qualcomm | sc8380xp |
| qualcomm | snapdragon_ar1_gen_1_firmware |
| qualcomm | snapdragon_ar1_gen_1 |
| qualcomm | wcd9378c_firmware |
| qualcomm | wcd9378c |
| qualcomm | wcd9380_firmware |
| qualcomm | wcd9380 |
| qualcomm | wcd9385_firmware |
| qualcomm | wcd9385 |
| qualcomm | wcn7861_firmware |
| qualcomm | wcn7861 |
| qualcomm | wcn7880_firmware |
| qualcomm | wcn7880 |
| qualcomm | wsa8830_firmware |
| qualcomm | wsa8830 |
| qualcomm | wsa8832_firmware |
| qualcomm | wsa8832 |
| qualcomm | wsa8835_firmware |
| qualcomm | wsa8835 |
| qualcomm | wsa8840_firmware |
| qualcomm | wsa8840 |
| qualcomm | wsa8845_firmware |
| qualcomm | wsa8845 |
| qualcomm | wsa8845h_firmware |
| qualcomm | wsa8845h |
| qualcomm | x2000077_firmware |
| qualcomm | x2000077 |
| qualcomm | x2000086_firmware |
| qualcomm | x2000086 |
| qualcomm | x2000090_firmware |
| qualcomm | x2000090 |
| qualcomm | x2000092_firmware |
| qualcomm | x2000092 |
| qualcomm | x2000094_firmware |
| qualcomm | x2000094 |
| qualcomm | xg101002_firmware |
| qualcomm | xg101002 |
| qualcomm | xg101032_firmware |
| qualcomm | xg101032 |
| qualcomm | xg101039_firmware |
| qualcomm | xg101039 |
References
Frequently Asked Questions
What is CVE-2026-25266? +
How severe is CVE-2026-25266? +
What products are affected by CVE-2026-25266? +
How do I check if I'm vulnerable to CVE-2026-25266? +
Related Vulnerabilities
A client-side security misconfiguration vulnerability exists in OpenBlow whistleblowing platform across multiple versions and default deployments, due to the absence …
Voltronic Power ViewPower through 1.04-24215, ViewPower Pro through 2.0-22165, and PowerShield Netguard before 1.04-23292 allows a remote attacker to run …
A missing authentication for critical function vulnerability has been reported to affect myQNAPcloud Link. If exploited, the vulnerability could allow …
An issue was discovered in MISP before 2.4.184. A client does not need to use POST to start an export …
langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-44467 fix and execute arbitrary code …
Voltronic Power ViewPower Pro updateManagerPassword Exposed Dangerous Function Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on …