CVE-2025-48507 - CVE House
Back to Database
Status published High CVE-2025-48507

The security state of the calling processor into Trusted Firmware...

Vulnerability Description

The security state of the calling processor into Trusted Firmware (TF-A) is not used and could potentially allow non-secure processors access to secure memories, access to crypto operations, and the ability to turn on and off subsystems within the SOC.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-48507

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Kria™ SOM, Zynq™ UltraScale+™ MPSoCs, Zynq™ UltraScale+™ RFSoCs
Vulnerable Versions:
Version TBD

Timeline

Official Publish: November 23rd, 2025
Last Modified: January 14th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.