PT-2025-24373 · Quantenna · Quantenna Wi-Fi Chipset

·

CVE-2025-3459

·

Published

2025-03-27

·

Updated

2026-01-21

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Quantenna Wi-Fi chipset versions prior to 8.0.0.28
Description The Quantenna Wi-Fi chipset ships with a local control script, transmit file, that is vulnerable to command injection. This issue is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command (Argument Injection)". The vendor has released a best practices guide for implementors of this chipset.
Recommendations For versions prior to 8.0.0.28, consider disabling the transmit file script until a patch is available. Implement the best practices guide provided by the vendor to minimize the risk of exploitation.

Fix

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06625
CVE-2025-3459

Affected Products

Quantenna Wi-Fi Chipset