Buffer Overflow Vulnerability in NXP Wi-Fi Driver
CVE-2025-29338

5.6MEDIUM

Key Information:

Vendor

NXP

Vendor
CVE Published:
13 May 2026

What is CVE-2025-29338?

A critical buffer overflow vulnerability has been identified in the NXP moal.ko Wi-Fi driver version 5.1.7.10. This issue arises through improper handling of the mod_para parameter within the woal_init_module_param function. Exploiting this vulnerability could lead to unintended memory access, potentially allowing an attacker to execute arbitrary code and gain unauthorized control over affected systems. Users are strongly advised to review their firmware versions and apply necessary updates to mitigate the risk.

References

CVSS V3.1

Score:
5.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.