{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2025-47400",
        "tracking": {
            "current_release_date": "2026-06-02T02:42:17.317479Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2025-47400",
            "initial_release_date": "2025-06-20T12:27:09.740414Z",
            "revision_history": [
                {
                    "date": "2025-06-20T12:27:09.740414Z",
                    "number": "1",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-04-06T16:27:00.885336Z",
                    "number": "2",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-04-06T16:27:05.184034Z",
                    "number": "3",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-04-06T16:40:49.953897Z",
                    "number": "4",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (11).| References created (1).| CWES updated (1).| Unknown change."
                },
                {
                    "date": "2026-04-06T16:40:55.090407Z",
                    "number": "5",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-04-07T17:00:32.724512Z",
                    "number": "6",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-04-08T21:26:38.300780Z",
                    "number": "7",
                    "summary": "Products connected (11).| Product Identifiers created (11)."
                },
                {
                    "date": "2026-04-08T21:26:46.271747Z",
                    "number": "8",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-04-11T15:02:02.200872Z",
                    "number": "9",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-06-01T18:41:03.986068Z",
                    "number": "10",
                    "summary": "Source connected.| CVE status created. (valid)| Products connected (1).| Vendor_assessment created."
                },
                {
                    "date": "2026-06-01T18:41:06.678270Z",
                    "number": "11",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-06-02T02:42:16.614423Z",
                    "number": "12",
                    "summary": "Source connected.| CVE status created. (valid)"
                }
            ],
            "status": "interim",
            "version": "12"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:android/unknown",
                                "product": {
                                    "name": "vers:android/unknown",
                                    "product_id": "CSAFPID-1961212"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Closed-source component"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/pandeiro",
                                "product": {
                                    "name": "vers:unknown/pandeiro",
                                    "product_id": "CSAFPID-5499810"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/snapdragon8elitegen5",
                                "product": {
                                    "name": "vers:unknown/snapdragon8elitegen5",
                                    "product_id": "CSAFPID-5499834"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sw6100",
                                "product": {
                                    "name": "vers:unknown/sw6100",
                                    "product_id": "CSAFPID-5499835"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sw6100p",
                                "product": {
                                    "name": "vers:unknown/sw6100p",
                                    "product_id": "CSAFPID-5499836"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/themisto",
                                "product": {
                                    "name": "vers:unknown/themisto",
                                    "product_id": "CSAFPID-5499837"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/wcd9395",
                                "product": {
                                    "name": "vers:unknown/wcd9395",
                                    "product_id": "CSAFPID-1323670"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/wcn7860",
                                "product": {
                                    "name": "vers:unknown/wcn7860",
                                    "product_id": "CSAFPID-1323673"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/wcn7861",
                                "product": {
                                    "name": "vers:unknown/wcn7861",
                                    "product_id": "CSAFPID-1323674"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/wsa8840",
                                "product": {
                                    "name": "vers:unknown/wsa8840",
                                    "product_id": "CSAFPID-1323677"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/wsa8845",
                                "product": {
                                    "name": "vers:unknown/wsa8845",
                                    "product_id": "CSAFPID-1323678"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/wsa8845h",
                                "product": {
                                    "name": "vers:unknown/wsa8845h",
                                    "product_id": "CSAFPID-1323679"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Snapdragon"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-1301893",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:qualcomm:wcd9395_firmware:-:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "WCD9395 Firmware"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-1301878",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:qualcomm:wsa8840_firmware:-:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "WSA8840 Firmware"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-1301876",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:qualcomm:wsa8845h_firmware:-:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "WSA8845H Firmware"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-2462396",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:qualcomm:wcn7860_firmware:-:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "wcn7860_firmware"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-2462328",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:qualcomm:wcn7861_firmware:-:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "wcn7861_firmware"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-2166512",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:qualcomm:wsa8845_firmware:-:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "wsa8845_firmware"
                    }
                ],
                "category": "vendor",
                "name": "Qualcomm"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-5757141",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:qualcomm:pandeiro_firmware:-:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "pandeiro_firmware"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-5757161",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:qualcomm:snapdragon_8_elite_gen_5_firmware:-:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "snapdragon_8_elite_gen_5_firmware"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-5757142",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:qualcomm:sw6100_firmware:-:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "sw6100_firmware"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-5757143",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:qualcomm:sw6100p_firmware:-:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "sw6100p_firmware"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-5757144",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:qualcomm:themisto_firmware:-:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "themisto_firmware"
                    }
                ],
                "category": "vendor",
                "name": "qualcomm"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2025-47400",
            "cwe": {
                "id": "CWE-126",
                "name": "Buffer Over-read"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "Cryptographic issue while copying data to a destination buffer without validating its size.",
                    "title": "nvd - https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-47400"
                },
                {
                    "category": "description",
                    "text": "Cryptographic issue while copying data to a destination buffer without validating its size.",
                    "title": "cveprojectv5 - https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/47xxx/CVE-2025-47400.json"
                },
                {
                    "category": "other",
                    "text": "4e-05",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "6.1",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "There is product data available from source Android, Is related to (a version of) an uncommon product",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "details",
                    "text": "Severity: 3\n",
                    "title": "Vendor assessment"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1323670",
                    "CSAFPID-1323673",
                    "CSAFPID-1323674",
                    "CSAFPID-1323677",
                    "CSAFPID-1323678",
                    "CSAFPID-1323679",
                    "CSAFPID-5499810",
                    "CSAFPID-5499834",
                    "CSAFPID-5499835",
                    "CSAFPID-5499836",
                    "CSAFPID-5499837",
                    "CSAFPID-1301876",
                    "CSAFPID-1301878",
                    "CSAFPID-1301893",
                    "CSAFPID-2166512",
                    "CSAFPID-2462328",
                    "CSAFPID-2462396",
                    "CSAFPID-5757141",
                    "CSAFPID-5757142",
                    "CSAFPID-5757143",
                    "CSAFPID-5757144",
                    "CSAFPID-5757161",
                    "CSAFPID-1961212"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-47400"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/47xxx/CVE-2025-47400.json"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=20000"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=30000"
                },
                {
                    "category": "external",
                    "summary": "Source - android",
                    "url": "https://source.android.com/docs/security/bulletin/2026/2026-06-01"
                },
                {
                    "category": "external",
                    "summary": "Source - hkcert",
                    "url": "https://www.hkcert.org/security-bulletin/android-multiple-vulnerabilities_20260602"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd",
                    "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2026-bulletin.html"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1301876",
                        "CSAFPID-1301878",
                        "CSAFPID-1301893",
                        "CSAFPID-1323670",
                        "CSAFPID-1323673",
                        "CSAFPID-1323674",
                        "CSAFPID-1323677",
                        "CSAFPID-1323678",
                        "CSAFPID-1323679",
                        "CSAFPID-1961212",
                        "CSAFPID-2166512",
                        "CSAFPID-2462328",
                        "CSAFPID-2462396",
                        "CSAFPID-5499810",
                        "CSAFPID-5499834",
                        "CSAFPID-5499835",
                        "CSAFPID-5499836",
                        "CSAFPID-5499837",
                        "CSAFPID-5757141",
                        "CSAFPID-5757142",
                        "CSAFPID-5757143",
                        "CSAFPID-5757144",
                        "CSAFPID-5757161"
                    ]
                }
            ],
            "title": "CVE-2025-47400"
        }
    ]
}