6.3

CVE-2026-25262

Write-what-where Condition in Primary Bootloader

Memory corruption while processing a crafted ELF file in the Primary Bootloader.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qualcomm ≫ Mdm9207 Firmware Version -
   Qualcomm ≫ Mdm9207 Version -
Qualcomm ≫ Mdm9655 Firmware Version -
   Qualcomm ≫ Mdm9655 Version -
Qualcomm ≫ Mdm9665 Firmware Version -
   Qualcomm ≫ Mdm9665 Version -
Qualcomm ≫ Msm8909 Firmware Version -
   Qualcomm ≫ Msm8909 Version -
Qualcomm ≫ Msm8916 Firmware Version -
   Qualcomm ≫ Msm8916 Version -
Qualcomm ≫ Msm8952 Firmware Version -
   Qualcomm ≫ Msm8952 Version -
Qualcomm ≫ Sdx50 Firmware Version -
   Qualcomm ≫ Sdx50 Version -
Qualcomm ≫ Mdm9645 Firmware Version -
   Qualcomm ≫ Mdm9645 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.107
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.3 0.4 5.9
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Qualcomm 6.9 0.3 6
CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
CWE-123 Write-what-where Condition

Any condition where the attacker has the ability to write an arbitrary value to an arbitrary location, often as the result of a buffer overflow.

https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2026-bulletin.html
Vendor Advisory