Cyber Posture

CVE-2025-47348

High

Published: 07 January 2026

Published
07 January 2026
Modified
28 January 2026
KEV Added
Patch
CVSS Score 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0002 6.3th percentile
Risk Priority 16 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2025-47348 is a high-severity Use of Uninitialized Variable (CWE-457) vulnerability in Qualcomm Aqt1000 Firmware. Its CVSS base score is 7.8 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploitation for Privilege Escalation (T1068); ranked at the 6.3th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified are NIST 800-53 SI-16 (Memory Protection) and SI-2 (Flaw Remediation).

Threat & Defense at a Glance

What attackers do: exploitation maps to Exploitation for Privilege Escalation (T1068). What defenders deploy: see the NIST 800-53 controls recommended below.
Threat & Defense Details

Mitigating Controls (NIST 800-53 r5)AI

preventrecover

Directly mitigates CVE-2025-47348 by requiring timely patching of the use-after-free memory corruption flaw in the trusted application's identity credential processing.

prevent

Implements memory protection mechanisms such as address space randomization and data execution prevention to block exploitation of the use-after-free vulnerability during credential operations.

prevent

Isolates the trusted application as a security function, limiting the blast radius of local low-privilege exploitation of the memory corruption vulnerability.

MITRE ATT&CK Enterprise TechniquesAI

T1068 Exploitation for Privilege Escalation Privilege Escalation
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
Why these techniques?

Local memory corruption (UAF) in trusted app enables arbitrary code execution/privilege escalation from low-priv context.

Confidence: MEDIUM · MITRE ATT&CK Enterprise v18.1

NVD Description

Memory corruption while processing identity credential operations in the trusted application.

Deeper analysisAI

CVE-2025-47348 is a memory corruption vulnerability, classified under CWE-457 (Use After Free), that occurs while processing identity credential operations in the trusted application. It affects Qualcomm products, as detailed in their security bulletin. The vulnerability carries a CVSS v3.1 base score of 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) and was published on 2026-01-07T12:17:04.457.

A local attacker with low privileges can exploit this vulnerability through low-complexity means without requiring user interaction. Successful exploitation enables high-impact consequences across confidentiality, integrity, and availability, potentially leading to arbitrary code execution or disruption within the trusted application context.

Qualcomm's January 2026 security bulletin provides further details on the vulnerability, available at https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2026-bulletin.html, including information on affected products and recommended mitigations or patches.

Details

CWE(s)

Affected Products

qualcomm
aqt1000 firmware
all versions
qualcomm
ar8035 firmware
all versions
qualcomm
csra6620 firmware
all versions
qualcomm
csra6640 firmware
all versions
qualcomm
fastconnect 6200 firmware
all versions
qualcomm
qcs2290 firmware
all versions
qualcomm
qcs4490 firmware
all versions
qualcomm
qcs5430 firmware
all versions
qualcomm
qcs6125 firmware
all versions
qualcomm
qcs615 firmware
all versions
+194 more product configuration(s) — see NVD for full list

CVEs Like This One

CVE-2025-47346Same product: Qualcomm Ar8035
CVE-2025-47345Same product: Qualcomm Ar8035
CVE-2025-47386Same product: Qualcomm Ar8035
CVE-2025-47376Same product: Qualcomm Ar8035
CVE-2025-47375Same product: Qualcomm Ar8035
CVE-2025-47379Same product: Qualcomm Ar8035
CVE-2025-47373Same product: Qualcomm Ar8035
CVE-2025-47389Same product: Qualcomm Ar8035
CVE-2026-21385Same product: Qualcomm Ar8035
CVE-2024-53024Same product: Qualcomm Ar8035

References