Command Injection Vulnerability in Quantenna Wi-Fi Chipset by ON Semiconductor
CVE-2025-3460

7.7HIGH

What is CVE-2025-3460?

The Quantenna Wi-Fi chipset is exposed to a command injection vulnerability due to improper neutralization of argument delimiters in a control script. This flaw allows attackers to exploit the set_tx_pow script, leading to potential unauthorized command execution. Users and implementors are advised to follow best practices provided by the vendor to mitigate risks associated with this vulnerability.

Affected Version(s)

Quantenna Wi-Fi chipset 0 <= 8.0.0.28

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ricky "HeadlessZeke" Lawshae of Keysight
todb
.
CVE-2025-3460 : Command Injection Vulnerability in Quantenna Wi-Fi Chipset by ON Semiconductor