Command Injection Vulnerability in Quantenna Wi-Fi Chipset
CVE-2025-32456

7.7HIGH

What is CVE-2025-32456?

The Quantenna Wi-Fi chipset contains a local control script, router_command.sh, which is susceptible to command injection via the put_file_to_qtn argument. This security flaw arises from improper handling of argument delimiters, a category defined by CWE-88. The vulnerability poses a significant risk as it allows an attacker to execute arbitrary commands on the affected system. While the vendor has released a best practices guide for chipset implementors, the vulnerability remains unpatched in the latest SDK version 8.0.0.28 and below, putting users at risk if they do not follow recommended security protocols.

Affected Version(s)

Quantenna Wi-Fi chipset 0 <= 8.0.0.28

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ricky "HeadlessZeke" Lawshae of Keysight
todb
.
CVE-2025-32456 : Command Injection Vulnerability in Quantenna Wi-Fi Chipset