Cyber Posture

CVE-2025-47383

High

Published: 02 March 2026

Published
02 March 2026
Modified
04 March 2026
KEV Added
Patch
CVSS Score 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0002 5.4th percentile
Risk Priority 14 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2025-47383 is a high-severity Missing Cryptographic Step (CWE-325) vulnerability in Qualcomm 5G Fixed Wireless Access Platform Firmware. Its CVSS base score is 7.2 (High).

Operationally, ranked at the 5.4th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

Threat & Defense Details

MITRE ATT&CK Enterprise TechniquesAI

Insufficient information to map techniques.
Confidence: LOW · MITRE ATT&CK Enterprise v18.1

NVD Description

Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.

Deeper analysisAI

CVE-2025-47383 is a vulnerability in which weak configuration may lead to a cryptographic issue when a VoWiFi call is triggered from user equipment (UE). It is associated with CWE-325 (Missing Required Cryptographic Step) and affects Qualcomm components, as documented in their security bulletin. The vulnerability received a CVSS v3.1 base score of 7.2 (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H), indicating high severity due to network accessibility, low attack complexity, high confidentiality/integrity/availability impact, and unchanged scope.

An attacker with high privileges (PR:H) can exploit this vulnerability over the network (AV:N) with low complexity (AC:L) and without requiring user interaction (UI:N). Successful exploitation could result in high impacts to confidentiality, integrity, and availability (C:H/I:H/A:H), stemming from the cryptographic failure triggered by VoWiFi call initiation from the UE.

Qualcomm's March 2026 security bulletin provides details on the issue, including advisories and patches for mitigation, available at https://docs.qualcomm.com/product/publicresources/securitybulletin/march-2026-bulletin.html. The CVE was published on 2026-03-02T17:16:26.383.

Details

CWE(s)

Affected Products

qualcomm
5g fixed wireless access platform firmware
all versions
qualcomm
9206 lte modem firmware
all versions
qualcomm
9207 lte modem firmware
all versions
qualcomm
apq8098 firmware
all versions
qualcomm
aqt1000 firmware
all versions
qualcomm
qca8337 firmware
all versions
qualcomm
qca9367 firmware
all versions
qualcomm
qca9377 firmware
all versions
qualcomm
qcc710 firmware
all versions
qualcomm
qcm2290 firmware
all versions
+196 more product configuration(s) — see NVD for full list

CVEs Like This One

CVE-2025-47392Same product: Qualcomm 5G Fixed Wireless Access Platform
CVE-2026-21385Same product: Qualcomm 5G Fixed Wireless Access Platform
CVE-2025-47379Same product: Qualcomm 5G Fixed Wireless Access Platform
CVE-2025-47386Same product: Qualcomm Ar8035
CVE-2025-47376Same product: Qualcomm Ar8035
CVE-2025-47375Same product: Qualcomm Ar8035
CVE-2025-47348Same product: Qualcomm Aqt1000
CVE-2025-47377Same product: Qualcomm Ar8035
CVE-2025-47389Same product: Qualcomm Ar8035
CVE-2025-47373Same product: Qualcomm Ar8035

References