CVE-2025-48507

CVSS

No CVSS.

T

he security state of the calling processor into Trusted Firmware (TF-A) is not used and could potentially allow non-secure processors access to secure memories, access to crypto operations, and the ability to turn on and off subsystems within the SOC.

Configurations

No configuration.

History

14 Jan 2026, 19:16

Type Values Removed Values Added
Summary (en) The security state of the calling processor into Arm® Trusted Firmware (TF-A) is not used and could potentially allow non-secure processors access to secure memories, access to crypto operations, and the ability to turn on and off subsystems within the SOC. (en) The security state of the calling processor into Trusted Firmware (TF-A) is not used and could potentially allow non-secure processors access to secure memories, access to crypto operations, and the ability to turn on and off subsystems within the SOC.

23 Nov 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-23 17:15

Updated : 2026-01-14 19:16


NVD link : CVE-2025-48507

Mitre link : CVE-2025-48507

CVE.ORG link : CVE-2025-48507


JSON object : View

Products Affected

No product.

CWE
CWE-1284

Improper Validation of Specified Quantity in Input