Skip to content
Security Alerts

CVE-2026-25293: Buffer overflow in Qualcomm PLC Firmware

A buffer overflow caused by incorrect authorization in Qualcomm PLC firmware allows an attacker on an adjacent network to impact device confidentiality, integrity and availability...

Summary

ParameterValue
CVE IDCVE-2026-25293
Alert SourceGitHub Advisory - Critical Vulnerability
CVE Publication Year2026
Date Published2026-05-04
VendorQualcomm
ProductPLC Firmware
CVSS Score9.6 (critical)
EPSS ScoreNo data
CISA KEVNo
RansomwareNot confirmed

Vulnerability Description

Buffer overflow due to incorrect authorization in Qualcomm PLC (Power Line Communication) firmware. The attack vector is adjacent network, requires no privileges or user interaction, and leads to high impact on confidentiality, integrity and availability. Details about specific affected models and firmware versions are available in the Qualcomm security bulletin.

Required Actions

Update Qualcomm PLC firmware to the version containing the security fix as listed in the vendor bulletin. Identify devices in your infrastructure that use Qualcomm Powerline chipsets (e.g. HomePlug AV adapters, smart home devices) and coordinate the update schedule with the hardware supplier. Until patches are deployed, restrict access to network segments where vulnerable devices operate.

Who Is Affected?

This vulnerability affects products with PLC Firmware by Qualcomm. Check the Qualcomm bulletin for the specific chipset models and OEM hardware built on top of them, then verify whether your infrastructure runs vulnerable firmware versions.

Sources


Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.

Learn More

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist