Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.
Conclusion & alert: CVE-2025-21428 is rated Low Risk (33.4/100): CVSS High severity, with low exploitation likelihood (EPSS 0.21%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.56% | 0.21% | -0.35% |
| 2 | 2026-05-18 | 0.35% | 0.56% | +0.20% |
| 3 | 2026-02-01 | — | 0.35% | — |
Full EPSS history (7 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| qualcomm | snapdragon_439_mobile_platform_firmware | — | cpe:2.3:o:qualcomm:snapdragon_439_mobile_platform_firmware:-:*:*:*:*:*:*:* |
| qualcomm | snapdragon_625_mobile_platform_firmware | — | cpe:2.3:o:qualcomm:snapdragon_625_mobile_platform_firmware:-:*:*:*:*:*:*:* |
| qualcomm | snapdragon_626_mobile_platform_firmware | — | cpe:2.3:o:qualcomm:snapdragon_626_mobile_platform_firmware:-:*:*:*:*:*:*:* |
| qualcomm | snapdragon_632_mobile_platform_firmware | — | cpe:2.3:o:qualcomm:snapdragon_632_mobile_platform_firmware:-:*:*:*:*:*:*:* |
| qualcomm | snapdragon_820_automotive_platform_firmware | — | cpe:2.3:o:qualcomm:snapdragon_820_automotive_platform_firmware:-:*:*:*:*:*:*:* |
| qualcomm | snapdragon_auto_5g_modem-rf_firmware | — | cpe:2.3:o:qualcomm:snapdragon_auto_5g_modem-rf_firmware:-:*:*:*:*:*:*:* |
| qualcomm | snapdragon_x12_lte_modem_firmware | — | cpe:2.3:o:qualcomm:snapdragon_x12_lte_modem_firmware:-:*:*:*:*:*:*:* |
| qualcomm | snapdragon_x35_5g_modem-rf_system_firmware | — | cpe:2.3:o:qualcomm:snapdragon_x35_5g_modem-rf_system_firmware:-:*:*:*:*:*:*:* |
| qualcomm | snapdragon_x5_lte_modem_firmware | — | cpe:2.3:o:qualcomm:snapdragon_x5_lte_modem_firmware:-:*:*:*:*:*:*:* |
| qualcomm | vision_intelligence_100_platform_\(apq8053-aa\)_firmware | — | cpe:2.3:o:qualcomm:vision_intelligence_100_platform_\(apq8053-aa\)_firmware:-:*:*:*:*:*:*:* |
| qualcomm | vision_intelligence_200_platform_\(apq8053-ac\)_firmware | — | cpe:2.3:o:qualcomm:vision_intelligence_200_platform_\(apq8053-ac\)_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcd9326_firmware | — | cpe:2.3:o:qualcomm:wcd9326_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcd9330_firmware | — | cpe:2.3:o:qualcomm:wcd9330_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcd9335_firmware | — | cpe:2.3:o:qualcomm:wcd9335_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcd9340_firmware | — | cpe:2.3:o:qualcomm:wcd9340_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcn3610_firmware | — | cpe:2.3:o:qualcomm:wcn3610_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcn3615_firmware | — | cpe:2.3:o:qualcomm:wcn3615_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcn3620_firmware | — | cpe:2.3:o:qualcomm:wcn3620_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcn3660b_firmware | — | cpe:2.3:o:qualcomm:wcn3660b_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcn3680_firmware | — | cpe:2.3:o:qualcomm:wcn3680_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcn3680b_firmware | — | cpe:2.3:o:qualcomm:wcn3680b_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcn3980_firmware | — | cpe:2.3:o:qualcomm:wcn3980_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wsa8810_firmware | — | cpe:2.3:o:qualcomm:wsa8810_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wsa8815_firmware | — | cpe:2.3:o:qualcomm:wsa8815_firmware:-:*:*:*:*:*:*:* |
| qualcomm | 9206_lte_modem_firmware | — | cpe:2.3:o:qualcomm:9206_lte_modem_firmware:-:*:*:*:*:*:*:* |
| qualcomm | apq8017_firmware | — | cpe:2.3:o:qualcomm:apq8017_firmware:-:*:*:*:*:*:*:* |
| qualcomm | ar8031_firmware | — | cpe:2.3:o:qualcomm:ar8031_firmware:-:*:*:*:*:*:*:* |
| qualcomm | c-v2x_9150_firmware | — | cpe:2.3:o:qualcomm:c-v2x_9150_firmware:-:*:*:*:*:*:*:* |
| qualcomm | csra6620_firmware | — | cpe:2.3:o:qualcomm:csra6620_firmware:-:*:*:*:*:*:*:* |
| qualcomm | csra6640_firmware | — | cpe:2.3:o:qualcomm:csra6640_firmware:-:*:*:*:*:*:*:* |
| qualcomm | fastconnect_6200_firmware | — | cpe:2.3:o:qualcomm:fastconnect_6200_firmware:-:*:*:*:*:*:*:* |
| qualcomm | fastconnect_6900_firmware | — | cpe:2.3:o:qualcomm:fastconnect_6900_firmware:-:*:*:*:*:*:*:* |
| qualcomm | mdm9250_firmware | — | cpe:2.3:o:qualcomm:mdm9250_firmware:-:*:*:*:*:*:*:* |
| qualcomm | mdm9628_firmware | — | cpe:2.3:o:qualcomm:mdm9628_firmware:-:*:*:*:*:*:*:* |
| qualcomm | mdm9640_firmware | — | cpe:2.3:o:qualcomm:mdm9640_firmware:-:*:*:*:*:*:*:* |
| qualcomm | mdm9650_firmware | — | cpe:2.3:o:qualcomm:mdm9650_firmware:-:*:*:*:*:*:*:* |
| qualcomm | msm8996au_firmware | — | cpe:2.3:o:qualcomm:msm8996au_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6174_firmware | — | cpe:2.3:o:qualcomm:qca6174_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6174a_firmware | — | cpe:2.3:o:qualcomm:qca6174a_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6175a_firmware | — | cpe:2.3:o:qualcomm:qca6175a_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6554a_firmware | — | cpe:2.3:o:qualcomm:qca6554a_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6564a_firmware | — | cpe:2.3:o:qualcomm:qca6564a_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6564au_firmware | — | cpe:2.3:o:qualcomm:qca6564au_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6574_firmware | — | cpe:2.3:o:qualcomm:qca6574_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6574a_firmware | — | cpe:2.3:o:qualcomm:qca6574a_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6574au_firmware | — | cpe:2.3:o:qualcomm:qca6574au_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6584_firmware | — | cpe:2.3:o:qualcomm:qca6584_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6584au_firmware | — | cpe:2.3:o:qualcomm:qca6584au_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6595_firmware | — | cpe:2.3:o:qualcomm:qca6595_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6595au_firmware | — | cpe:2.3:o:qualcomm:qca6595au_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6696_firmware | — | cpe:2.3:o:qualcomm:qca6696_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca9367_firmware | — | cpe:2.3:o:qualcomm:qca9367_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca9377_firmware | — | cpe:2.3:o:qualcomm:qca9377_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca9379_firmware | — | cpe:2.3:o:qualcomm:qca9379_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcm2150_firmware | — | cpe:2.3:o:qualcomm:qcm2150_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qep8111_firmware | — | cpe:2.3:o:qualcomm:qep8111_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qualcomm_205_mobile_platform_firmware | — | cpe:2.3:o:qualcomm:qualcomm_205_mobile_platform_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qualcomm_215_mobile_platform_firmware | — | cpe:2.3:o:qualcomm:qualcomm_215_mobile_platform_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa2150p_firmware | — | cpe:2.3:o:qualcomm:sa2150p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd626_firmware | — | cpe:2.3:o:qualcomm:sd626_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sdm429w_firmware | — | cpe:2.3:o:qualcomm:sdm429w_firmware:-:*:*:*:*:*:*:* |
| qualcomm | smart_audio_200_platform_firmware | — | cpe:2.3:o:qualcomm:smart_audio_200_platform_firmware:-:*:*:*:*:*:*:* |
| qualcomm | smart_audio_400_platform_firmware | — | cpe:2.3:o:qualcomm:smart_audio_400_platform_firmware:-:*:*:*:*:*:*:* |
| qualcomm | smart_display_200_platform_\(apq5053-aa\)_firmware | — | cpe:2.3:o:qualcomm:smart_display_200_platform_\(apq5053-aa\)_firmware:-:*:*:*:*:*:*:* |
| qualcomm | snapdragon_1200_wearable_platform_firmware | — | cpe:2.3:o:qualcomm:snapdragon_1200_wearable_platform_firmware:-:*:*:*:*:*:*:* |
| qualcomm | snapdragon_210_processor_firmware | — | cpe:2.3:o:qualcomm:snapdragon_210_processor_firmware:-:*:*:*:*:*:*:* |
| qualcomm | snapdragon_212_mobile_platform_firmware | — | cpe:2.3:o:qualcomm:snapdragon_212_mobile_platform_firmware:-:*:*:*:*:*:*:* |
| qualcomm | snapdragon_425_mobile_platform_firmware | — | cpe:2.3:o:qualcomm:snapdragon_425_mobile_platform_firmware:-:*:*:*:*:*:*:* |
| qualcomm | snapdragon_429_mobile_platform_firmware | — | cpe:2.3:o:qualcomm:snapdragon_429_mobile_platform_firmware:-:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html | Vendor Advisory |