Junglewise Threat Intelligence

CVE-2025-59601: Qualcomm Powerline Interface information disclosure during factory reset

CVE-2025-59601 · Severity: medium · CVSS 6.5 · Published 2026-06-01

Vendors: Qualcomm.

Executive brief

A security vulnerability exists in certain Qualcomm powerline communication devices that occurs during the factory reset process. An attacker physically located on the same local powerline network could intercept sensitive configuration data when a user attempts to wipe the device. This could lead to the exposure of private network settings or credentials, potentially compromising the security of the home or office network.

Technical details

This vulnerability is classified as an exposure of sensitive information through metadata (CWE-1230) within the powerline interface of Qualcomm chipsets. The flaw is triggered when a device is reset to factory default settings, during which sensitive configuration parameters are leaked over the powerline medium. An unauthenticated attacker on the same adjacent Layer 2 network (the powerline segment) can capture this data without user interaction. This allows for the unauthorized retrieval of device configurations, which may include network identifiers or security keys. The issue was disclosed in Qualcomm's June 2026 security bulletin.

Affected products

  • Qualcomm Powerline Chipset Firmware

Timeline

  • 2026-06-01: advisory: Published in Qualcomm June 2026 security bulletin
  • 2026-06-01: disclosed

References