Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ CVE-2025-59606 — cologne-firmware

🟠 CVSS 7.8 — High ✅ No Known Exploit CWE-476 NVD
7.8
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization.

How this vulnerability can be exploited

This issue can be reached with local access to the system, attack complexity is low, an attacker needs low-level privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality high, integrity high, availability high.

CVSS metrics in full

The score comes from this vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

  • Attack vector: Local — a local account, shell or session on the host is needed.
  • Attack complexity: Low — the attack works reliably, with no preparation.
  • Privileges required: Low — an ordinary user account is enough.
  • User interaction: None — nobody has to be tricked into anything.
  • Scope: Unchanged — the damage stays inside the vulnerable component.
  • Confidentiality impact: High — total loss, or loss the attacker controls.
  • Integrity impact: High — total loss, or loss the attacker controls.
  • Availability impact: High — total loss, or loss the attacker controls.

Weakness class

CVE-2025-59606 is classified as CWE-476: NULL Pointer Dereference. A pointer that can be null is used without a check, crashing the process.

Affected software

CVE-2025-59606 is recorded against 141 packages.

  • cologne-firmware
  • cq7790-firmware
  • cq8725s-firmware
  • cq8750m-firmware
  • fastconnect-6200-firmware
  • fastconnect-6700-firmware
  • fastconnect-6900-firmware
  • fastconnect-7800-firmware
  • g2-gen-1-firmware
  • iq-615-firmware
  • iq-8275-firmware
  • iq-9075-firmware
  • lemans-au-lgit-firmware
  • lemansau-firmware
  • molokai-firmware
  • monaco-iot-firmware
  • netrani-firmware
  • orne-firmware
  • palawan25-firmware
  • pandeiro-firmware
  • qam8255p-firmware
  • qam8295p-firmware
  • qam8397p-firmware
  • qam8620p-firmware
Show the remaining 117 packages
  • qam8797p-firmware
  • qamsrv1h-firmware
  • qamsrv1m-firmware
  • qca6574-firmware
  • qca6574a-firmware
  • qca6574au-firmware
  • qca6595-firmware
  • qca6595au-firmware
  • qca6678aq-firmware
  • qca6688aq-firmware
  • qca6696-firmware
  • qca6698aq-firmware
  • qca6797aq-firmware
  • qca8695au-firmware
  • qcm5430-firmware
  • qcm6490-firmware
  • qcm8838-firmware
  • qdu1000-firmware
  • qdu1110-firmware
  • qdu1210-firmware
  • qdx1010-firmware
  • qdx1011-firmware
  • qln1083bd-firmware
  • qln1086bd-firmware
  • qmb715-firmware
  • qmp1000-firmware
  • qmp2001-firmware
  • qpa1083bd-firmware
  • qpa1086bd-firmware
  • qualcomm-dragonwing-x100-accelerator-card-firmware
  • qxm1093-firmware
  • qxm1094-firmware
  • qxm1095-firmware
  • qxm1096-firmware
  • sa6145p-firmware
  • sa6150p-firmware
  • sa6155p-firmware
  • sa7255p-firmware
  • sa7775p-firmware
  • sa8145p-firmware
  • sa8150p-firmware
  • sa8155p-firmware
  • sa8195p-firmware
  • sa8255p-firmware
  • sa8295p-firmware
  • sa8540p-firmware
  • sa8620p-firmware
  • sa8770p-firmware
  • sa9000p-firmware
  • sdr753-firmware
  • sm4850-firmware
  • sm4850p-firmware
  • sm6450p-firmware
  • sm6475p-firmware
  • sm6475q-firmware
  • sm6850-firmware
  • sm7435-firmware
  • sm7435p-firmware
  • sm7635p-firmware
  • sm8735p-firmware
  • sm8750p-firmware
  • sm8845p-firmware
  • snapdragon-4-gen-2-mobile-platform-firmware
  • snapdragon-460-mobile-platform-firmware
  • snapdragon-6-gen-1-mobile-platform-firmware
  • snapdragon-6-gen-3-mobile-platform-firmware
  • snapdragon-662-mobile-platform-firmware
  • snapdragon-680-4g-mobile-platform-firmware
  • snapdragon-685-4g-mobile-platform-firmware
  • snapdragon-7-gen-4-mobile-platform-firmware
  • snapdragon-8-elite-firmware
  • snapdragon-8-elite-gen-5-firmware
  • snapdragon-wear-elite-platform-firmware
  • srv1h-firmware
  • srv1l-firmware
  • srv1m-firmware
  • sxr2330p-firmware
  • sxr2350p-firmware
  • themisto-firmware
  • video-collaboration-vc3-platform-firmware
  • wcd9370-firmware
  • wcd9375-firmware
  • wcd9378-firmware
  • wcd9378c-firmware
  • wcd9380-firmware
  • wcd9385-firmware
  • wcd9395-firmware
  • wcn3950-firmware
  • wcn3988-firmware
  • wcn6450-firmware
  • wcn6755-firmware
  • wcn7760-firmware
  • wcn7860-firmware
  • wcn7861-firmware
  • wcn7880-firmware
  • wcn7881-firmware
  • wsa8810-firmware
  • wsa8815-firmware
  • wsa8830-firmware
  • wsa8832-firmware
  • wsa8835-firmware
  • wsa8840-firmware
  • wsa8845-firmware
  • wsa8845h-firmware
  • wsa8850-firmware
  • wsa8850w-firmware
  • wsa8855c-firmware
  • x2000077-firmware
  • x2000086-firmware
  • x2000090-firmware
  • x2000092-firmware
  • x2000094-firmware
  • xg101002-firmware
  • xg101032-firmware
  • xg101039-firmware
  • xrv7209-firmware
  • xrv9209-firmware

Timeline and source

Published on 1 June 2026 and last revised on 22 July 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.

References

docs.qualcomm.com

Other advisories for this package

cologne-firmware has other advisories on record. If you are patching this one, these are worth checking on the same host:

Same weakness in other software

These advisories are the same class of weakness (CWE-476: NULL Pointer Dereference) in other software:

Details

Severity HIGH
CVSS Score 7.8
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE CWE-476
Public Exploit ✅ No
Source NVD
Published 2026-06-01
Updated 2026-08-20
Modified 2026-07-22
Fix URL N/A

Affected Packages

Software From version Fixed in
cologne-firmware
cq7790-firmware
cq8725s-firmware
cq8750m-firmware
fastconnect-6200-firmware
fastconnect-6700-firmware
fastconnect-6900-firmware
fastconnect-7800-firmware
g2-gen-1-firmware
iq-615-firmware
iq-8275-firmware
iq-9075-firmware
lemans-au-lgit-firmware
lemansau-firmware
molokai-firmware
monaco-iot-firmware
netrani-firmware
orne-firmware
palawan25-firmware
pandeiro-firmware
qam8255p-firmware
qam8295p-firmware
qam8397p-firmware
qam8620p-firmware
qam8797p-firmware
qamsrv1h-firmware
qamsrv1m-firmware
qca6574-firmware
qca6574a-firmware
qca6574au-firmware
qca6595-firmware
qca6595au-firmware
qca6678aq-firmware
qca6688aq-firmware
qca6696-firmware
qca6698aq-firmware
qca6797aq-firmware
qca8695au-firmware
qcm5430-firmware
qcm6490-firmware
qcm8838-firmware
qdu1000-firmware
qdu1110-firmware
qdu1210-firmware
qdx1010-firmware
qdx1011-firmware
qln1083bd-firmware
qln1086bd-firmware
qmb715-firmware
qmp1000-firmware
qmp2001-firmware
qpa1083bd-firmware
qpa1086bd-firmware
qualcomm-dragonwing-x100-accelerator-card-firmware
qxm1093-firmware
qxm1094-firmware
qxm1095-firmware
qxm1096-firmware
sa6145p-firmware
sa6150p-firmware
sa6155p-firmware
sa7255p-firmware
sa7775p-firmware
sa8145p-firmware
sa8150p-firmware
sa8155p-firmware
sa8195p-firmware
sa8255p-firmware
sa8295p-firmware
sa8540p-firmware
sa8620p-firmware
sa8770p-firmware
sa9000p-firmware
sdr753-firmware
sm4850-firmware
sm4850p-firmware
sm6450p-firmware
sm6475p-firmware
sm6475q-firmware
sm6850-firmware
sm7435-firmware
sm7435p-firmware
sm7635p-firmware
sm8735p-firmware
sm8750p-firmware
sm8845p-firmware
snapdragon-4-gen-2-mobile-platform-firmware
snapdragon-460-mobile-platform-firmware
snapdragon-6-gen-1-mobile-platform-firmware
snapdragon-6-gen-3-mobile-platform-firmware
snapdragon-662-mobile-platform-firmware
snapdragon-680-4g-mobile-platform-firmware
snapdragon-685-4g-mobile-platform-firmware
snapdragon-7-gen-4-mobile-platform-firmware
snapdragon-8-elite-firmware
snapdragon-8-elite-gen-5-firmware
snapdragon-wear-elite-platform-firmware
srv1h-firmware
srv1l-firmware
srv1m-firmware
sxr2330p-firmware
sxr2350p-firmware
themisto-firmware
video-collaboration-vc3-platform-firmware
wcd9370-firmware
wcd9375-firmware
wcd9378-firmware
wcd9378c-firmware
wcd9380-firmware
wcd9385-firmware
wcd9395-firmware
wcn3950-firmware
wcn3988-firmware
wcn6450-firmware
wcn6755-firmware
wcn7760-firmware
wcn7860-firmware
wcn7861-firmware
wcn7880-firmware
wcn7881-firmware
wsa8810-firmware
wsa8815-firmware
wsa8830-firmware
wsa8832-firmware
wsa8835-firmware
wsa8840-firmware
wsa8845-firmware
wsa8845h-firmware
wsa8850-firmware
wsa8850w-firmware
wsa8855c-firmware
x2000077-firmware
x2000086-firmware
x2000090-firmware
x2000092-firmware
x2000094-firmware
xg101002-firmware
xg101032-firmware
xg101039-firmware
xrv7209-firmware
xrv9209-firmware

Similar Threats

Site Security Check

Is cologne-firmware part of your stack?

CVE-2025-59606 is rated CVSS 7.8 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesCVECVE 2025