Cyber Posture

CVE-2025-47407

High

Published: 04 May 2026

Published
04 May 2026
Modified
06 May 2026
KEV Added
Patch
CVSS Score 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0001 1.6th percentile
Risk Priority 16 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2025-47407 is a high-severity Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367) vulnerability in Qualcomm Cq7790 Firmware. Its CVSS base score is 7.8 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploitation for Privilege Escalation (T1068); ranked at the 1.6th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified are NIST 800-53 SI-16 (Memory Protection) and SI-2 (Flaw Remediation).

Threat & Defense at a Glance

What attackers do: exploitation maps to Exploitation for Privilege Escalation (T1068). What defenders deploy: see the NIST 800-53 controls recommended below.
Threat & Defense Details

Mitigating Controls (NIST 800-53 r5)AI

prevent

SI-16 implements memory protection mechanisms that directly and comprehensively prevent exploitation of kernel-level memory corruption during DSP process creation due to allocation failure.

prevent

SI-2 requires timely remediation of the specific kernel allocation flaw causing memory corruption in Qualcomm DSP process creation.

prevent

SI-11 enforces proper error handling for kernel allocation failures, mitigating the mishandling that leads to memory corruption during DSP process creation.

MITRE ATT&CK Enterprise TechniquesAI

T1068 Exploitation for Privilege Escalation Privilege Escalation
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
Why these techniques?

Local kernel-level memory corruption (TOCTOU race condition) on DSP process creation directly enables local privilege escalation from low-privileged context with no user interaction.

Confidence: HIGH · MITRE ATT&CK Enterprise v18.1

NVD Description

Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level.

Deeper analysisAI

CVE-2025-47407 is a memory corruption vulnerability that occurs while creating a process on the digital signal processor due to allocation failure at the kernel level. It is associated with CWE-367 and affects Qualcomm components, as documented in their security bulletin. The vulnerability received a CVSS v3.1 base score of 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), indicating high severity with significant impacts on confidentiality, integrity, and availability.

A local attacker with low privileges can exploit this vulnerability with low attack complexity and no user interaction required. Successful exploitation leads to memory corruption, enabling high-level impacts such as unauthorized data access, modification, or denial of service on the affected DSP kernel.

Qualcomm's May 2026 security bulletin at https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2026-bulletin.html details the vulnerability, including affected products and recommended mitigations or patches. Security practitioners should consult this advisory for specific remediation guidance.

Details

CWE(s)

Affected Products

qualcomm
cq7790 firmware
all versions
qualcomm
cq8725s firmware
all versions
qualcomm
fastconnect 6200 firmware
all versions
qualcomm
fastconnect 6700 firmware
all versions
qualcomm
fastconnect 6900 firmware
all versions
qualcomm
fastconnect 7800 firmware
all versions
qualcomm
g2 gen 1 firmware
all versions
qualcomm
molokai firmware
all versions
qualcomm
netrani firmware
all versions
qualcomm
orne firmware
all versions
+90 more product configuration(s) — see NVD for full list

CVEs Like This One

CVE-2024-53028Same vendor: Qualcomm
CVE-2024-53032Same vendor: Qualcomm
CVE-2025-47385Same product: Qualcomm Fastconnect 6200
CVE-2025-59600Same product: Qualcomm Fastconnect 6200
CVE-2025-47388Same product: Qualcomm Fastconnect 6200
CVE-2025-47394Same product: Qualcomm Fastconnect 6200
CVE-2025-47396Same product: Qualcomm Fastconnect 6200
CVE-2025-47397Same product: Qualcomm Fastconnect 6200
CVE-2025-47398Same product: Qualcomm Fastconnect 6200
CVE-2025-47389Same product: Qualcomm Fastconnect 6200

References