CVE-2025-21457

Information disclosure while opening a fastrpc session when domain is not sanitized.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
qualcommCNA
6.1 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 1%
VendorProductVersion
qualcommar8035_firmware
-
qualcommfastconnect_7800_firmware
-
qualcommqca6584au_firmware
-
qualcommqca6698aq_firmware
-
qualcommqca8081_firmware
-
qualcommqca8337_firmware
-
qualcommqcc710_firmware
-
qualcommqcn6224_firmware
-
qualcommqcn6274_firmware
-
qualcommqfw7114_firmware
-
qualcommqfw7124_firmware
-
qualcommsnapdragon_auto_5g_modem-rf_gen_2_firmware
-
qualcommsnapdragon_x72_5g_modem-rf_system_firmware
-
qualcommsnapdragon_x75_5g_modem-rf_system_firmware
-
qualcommwcd9340_firmware
-
𝑥
= Vulnerable software versions