Memory corruption in video module due to buffer overflow while processing WAV file in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
Conclusion & alert: CVE-2022-25686 is rated Moderate Risk (47.9/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.30%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-10-31 | 0.17% | 0.30% | +0.13% |
| 2 | 2025-10-21 | 0.10% | 0.17% | +0.07% |
| 3 | 2025-03-30 | — | 0.10% | — |
Full EPSS history (8 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.3 | 3.1 | HIGH |
|
3.9 | 3.4 | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| qualcomm | apq8017_firmware | — | cpe:2.3:o:qualcomm:apq8017_firmware:-:*:*:*:*:*:*:* |
| qualcomm | apq8053_firmware | — | cpe:2.3:o:qualcomm:apq8053_firmware:-:*:*:*:*:*:*:* |
| qualcomm | aqt1000_firmware | — | cpe:2.3:o:qualcomm:aqt1000_firmware:-:*:*:*:*:*:*:* |
| qualcomm | msm8917_firmware | — | cpe:2.3:o:qualcomm:msm8917_firmware:-:*:*:*:*:*:*:* |
| qualcomm | msm8953_firmware | — | cpe:2.3:o:qualcomm:msm8953_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6390_firmware | — | cpe:2.3:o:qualcomm:qca6390_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6391_firmware | — | cpe:2.3:o:qualcomm:qca6391_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6420_firmware | — | cpe:2.3:o:qualcomm:qca6420_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6426_firmware | — | cpe:2.3:o:qualcomm:qca6426_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6430_firmware | — | cpe:2.3:o:qualcomm:qca6430_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6436_firmware | — | cpe:2.3:o:qualcomm:qca6436_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6574_firmware | — | cpe:2.3:o:qualcomm:qca6574_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6574a_firmware | — | cpe:2.3:o:qualcomm:qca6574a_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6574au_firmware | — | cpe:2.3:o:qualcomm:qca6574au_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6595au_firmware | — | cpe:2.3:o:qualcomm:qca6595au_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6696_firmware | — | cpe:2.3:o:qualcomm:qca6696_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcm2290_firmware | — | cpe:2.3:o:qualcomm:qcm2290_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcm4290_firmware | — | cpe:2.3:o:qualcomm:qcm4290_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcm6490_firmware | — | cpe:2.3:o:qualcomm:qcm6490_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs2290_firmware | — | cpe:2.3:o:qualcomm:qcs2290_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs4290_firmware | — | cpe:2.3:o:qualcomm:qcs4290_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs6490_firmware | — | cpe:2.3:o:qualcomm:qcs6490_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qualcomm215_firmware | — | cpe:2.3:o:qualcomm:qualcomm215_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa6155_firmware | — | cpe:2.3:o:qualcomm:sa6155_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa6155p_firmware | — | cpe:2.3:o:qualcomm:sa6155p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa8155_firmware | — | cpe:2.3:o:qualcomm:sa8155_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa8155p_firmware | — | cpe:2.3:o:qualcomm:sa8155p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa8195p_firmware | — | cpe:2.3:o:qualcomm:sa8195p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd_636_firmware | — | cpe:2.3:o:qualcomm:sd_636_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd_675_firmware | — | cpe:2.3:o:qualcomm:sd_675_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd_8_gen1_5g_firmware | — | cpe:2.3:o:qualcomm:sd_8_gen1_5g_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd429_firmware | — | cpe:2.3:o:qualcomm:sd429_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd439_firmware | — | cpe:2.3:o:qualcomm:sd439_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd460_firmware | — | cpe:2.3:o:qualcomm:sd460_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd480_firmware | — | cpe:2.3:o:qualcomm:sd480_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd632_firmware | — | cpe:2.3:o:qualcomm:sd632_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd660_firmware | — | cpe:2.3:o:qualcomm:sd660_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd662_firmware | — | cpe:2.3:o:qualcomm:sd662_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd665_firmware | — | cpe:2.3:o:qualcomm:sd665_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd670_firmware | — | cpe:2.3:o:qualcomm:sd670_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd675_firmware | — | cpe:2.3:o:qualcomm:sd675_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd678_firmware | — | cpe:2.3:o:qualcomm:sd678_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd680_firmware | — | cpe:2.3:o:qualcomm:sd680_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd690_5g_firmware | — | cpe:2.3:o:qualcomm:sd690_5g_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd695_firmware | — | cpe:2.3:o:qualcomm:sd695_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd710_firmware | — | cpe:2.3:o:qualcomm:sd710_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd720g_firmware | — | cpe:2.3:o:qualcomm:sd720g_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd730_firmware | — | cpe:2.3:o:qualcomm:sd730_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd750g_firmware | — | cpe:2.3:o:qualcomm:sd750g_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd765_firmware | — | cpe:2.3:o:qualcomm:sd765_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd765g_firmware | — | cpe:2.3:o:qualcomm:sd765g_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd768g_firmware | — | cpe:2.3:o:qualcomm:sd768g_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd778g_firmware | — | cpe:2.3:o:qualcomm:sd778g_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd780g_firmware | — | cpe:2.3:o:qualcomm:sd780g_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd835_firmware | — | cpe:2.3:o:qualcomm:sd835_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd855_firmware | — | cpe:2.3:o:qualcomm:sd855_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd865_5g_firmware | — | cpe:2.3:o:qualcomm:sd865_5g_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd870_firmware | — | cpe:2.3:o:qualcomm:sd870_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd888_firmware | — | cpe:2.3:o:qualcomm:sd888_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd888_5g_firmware | — | cpe:2.3:o:qualcomm:sd888_5g_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sdm630_firmware | — | cpe:2.3:o:qualcomm:sdm630_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sdx50m_firmware | — | cpe:2.3:o:qualcomm:sdx50m_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sdx55_firmware | — | cpe:2.3:o:qualcomm:sdx55_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sdx55m_firmware | — | cpe:2.3:o:qualcomm:sdx55m_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sdxr2_5g_firmware | — | cpe:2.3:o:qualcomm:sdxr2_5g_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sm4125_firmware | — | cpe:2.3:o:qualcomm:sm4125_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sm6250_firmware | — | cpe:2.3:o:qualcomm:sm6250_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sm7250p_firmware | — | cpe:2.3:o:qualcomm:sm7250p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sm7315_firmware | — | cpe:2.3:o:qualcomm:sm7315_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sm7325p_firmware | — | cpe:2.3:o:qualcomm:sm7325p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sm7450_firmware | — | cpe:2.3:o:qualcomm:sm7450_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sm8475_firmware | — | cpe:2.3:o:qualcomm:sm8475_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sm8475p_firmware | — | cpe:2.3:o:qualcomm:sm8475p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sw5100_firmware | — | cpe:2.3:o:qualcomm:sw5100_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sw5100p_firmware | — | cpe:2.3:o:qualcomm:sw5100p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcd9326_firmware | — | cpe:2.3:o:qualcomm:wcd9326_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcd9335_firmware | — | cpe:2.3:o:qualcomm:wcd9335_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcd9340_firmware | — | cpe:2.3:o:qualcomm:wcd9340_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcd9341_firmware | — | cpe:2.3:o:qualcomm:wcd9341_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcd9370_firmware | — | cpe:2.3:o:qualcomm:wcd9370_firmware:-:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://www.qualcomm.com/company/product-security/bulletins/september-2022-bulletin | Vendor Advisory |