Junglewise Threat Intelligence

CVE-2026-25275: Qualcomm WiFi chipset denial of service in FILS authentication frame handling

CVE-2026-25275 · Severity: high · CVSS 7.5 · Published 2026-09-17

Executive brief

Qualcomm's WiFi chipsets are vulnerable to a denial-of-service attack when processing malformed authentication frames that contain invalid FILS (Fast Initial Link Setup) information elements. An attacker on the network can send specially crafted WiFi authentication frames to cause the affected chipset to become temporarily unresponsive, disrupting wireless connectivity for affected devices.

Technical details

The vulnerability exists in the FILS information element parser within Qualcomm WiFi chipset firmware, which fails to properly validate the header length fields in authentication frames. When an attacker sends an authentication frame with an invalid FILS IE header length, the parser enters an error state causing a transient denial of service. The attack requires network-adjacent proximity (ability to transmit WiFi frames) but no prior authentication. The impact is temporary unresponsiveness of the WiFi chipset, requiring a reset or reconnection to restore service. Qualcomm has released firmware patches addressing this validation issue.

Affected products

  • Qualcomm WiFi Chipset Firmware <UNKNOWN>

Timeline

  • 2026-09-17: disclosed

References