Answer in brief
CVE-2026-25294 records a Unknown severity vulnerability in Buffer Over-read in WLAN Firmware. The current sources do not mark it as known exploited. The current feed maps Qualcomm, Inc./Snapdragon (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Qualcomm, Inc./Snapdragon (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Qualcomm, Inc./Snapdragongeneric | Cologne || Congo || CQ7790 || CQ7790M || CQ8845S || FastConnect 6200 || FastConnect 6700 || FastConnect 6900 || FastConnect 7800 || MBM715 || Orne || Palawan25 || Pandeiro || Q-7790 || QLN1083BD || QLN1086BD || QMP1000 || QMP2001 || QPA1083BD || QPA1086BD || Qualcomm FastConnect 8800 Mobile Connectivity System || QXM1093 || QXM1094 || QXM1095 || QXM1096 || SC8380XP || SM4875 || SM6850 || SM7675 || SM7675P || SM7750P || SM8635 || SM8635P || SM8650Q || SM8735P || SM8750P || SM8845P || SM8950 || SM8950P || SM8975 || SM8975P || Snapdragon 7 Gen 4 Mobile Platform || Snapdragon 8 Elite || Snapdragon 8 Elite Gen 5 || Snapdragon 8 Gen 3 Mobile Platform || Snapdragon 8 Gen 5 || SW-only || WCD9370 || WCD9375 || WCD9378 || WCD9380 || WCD9385 || WCD9390 || WCD9395 || WCN3988 || WCN6450 || WCN6755 || WCN7760 || WCN7860 || WCN7861 || WCN7880 || WCN7881 || WCN8841 || WSA8830 || WSA8832 || WSA8835 || WSA8840 || WSA8845 || WSA8845H || WSA8850 || WSA8850W || WSA8855C || X1E80100 || XRV7209 || XRV9209 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
Transient DOS while parsing frame during channel usage.
Quoted source text, attributed separately from HOL analysis.