« Volver al listado

Qualcomm

Qualcomm Fastconnect 6800 Firmware: vulnerabilidades y CVE

Qualcomm Fastconnect 6800 Firmware tiene 327 vulnerabilidades publicadas, 45 de ellas en los últimos 12 meses. 12 son críticas y 6 figuran en el catálogo de explotación activa de CISA.

CVE327
Últimos 12 meses45
Críticas12
Explotadas activamente6

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-21385Alta (7.8)1.3%⚠ Explotación activa2 mar 2026
Memory corruption while using alignments for memory allocation.
CVE-2025-21480Alta (8.6)0.46%⚠ Explotación activa3 jun 2025
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
CVE-2025-21479Alta (8.6)0.84%⚠ Explotación activa3 jun 2025
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
CVE-2024-43047Alta (7.8)0.67%⚠ Explotación activa7 oct 2024
Memory corruption while maintaining memory maps of HLOS memory.
CVE-2023-33107Alta (7.8)0.74%⚠ Explotación activa5 dic 2023
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.
CVE-2023-33106Alta (7.8)0.79%⚠ Explotación activa5 dic 2023
Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-25275Alta (7.5)0.19%—17 sept 2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
CVE-2026-24075Alta (7)0.06%—17 sept 2026
Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.
CVE-2026-24084Alta (7.5)0.25%—4 ago 2026
Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
CVE-2026-24079Alta (8.1)0.21%—4 ago 2026
Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
CVE-2026-24078Media (6.5)0.17%—4 ago 2026
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
CVE-2026-24077Media (6.5)0.17%—4 ago 2026
Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
CVE-2026-24076Media (6.7)0.11%—4 ago 2026
Memory Corruption when processing registry values with incorrect types using a direct query method.
CVE-2026-21379Alta (7.8)0.10%—6 jul 2026
Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.
CVE-2026-25277Alta (8.8)0.07%—1 jun 2026
Memory corruption while using Strongbox due to buffer overflow.
CVE-2026-25276Alta (8.8)0.07%—1 jun 2026
Memory corruption while using Strongbox due to missing bounds check.
CVE-2026-24091Alta (7.2)0.10%—1 jun 2026
Memory corruption while processing fastboot commands with improperly formatted input.
CVE-2026-24085Alta (7.2)0.10%—1 jun 2026
Memory Corruption when processing display command line information due to improper initialization of a variable.
CVE-2025-59611Media (6.7)0.08%—1 jun 2026
Memory corruption in diagnostic services due to absence of input validation
CVE-2025-59610Media (6.4)0.06%—1 jun 2026
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
CVE-2025-59605Alta (7.8)0.07%—1 jun 2026
Memory Corruption when processing device identifier strings that exceed the expected maximum length.
CVE-2025-59604Alta (7.8)0.07%—1 jun 2026
Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.
CVE-2025-47404Alta (7.8)0.07%—4 may 2026
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
CVE-2026-21378Alta (7.8)0.07%—6 abr 2026
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
CVE-2026-21376Alta (7.8)0.10%—6 abr 2026
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
CVE-2026-21374Alta (7.8)0.11%—6 abr 2026
Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validation.
CVE-2026-21373Alta (7.8)0.08%—6 abr 2026
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
CVE-2026-21371Alta (7.8)0.10%—6 abr 2026
Memory Corruption when retrieving output buffer with insufficient size validation.
CVE-2025-47392Alta (8.8)0.17%—6 abr 2026
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
CVE-2025-47389Alta (7.8)0.10%—6 abr 2026
Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
CVE-2026-21385Alta (7.8)1.3%⚠ Explotación activa2 mar 2026
Memory corruption while using alignments for memory allocation.
CVE-2025-47386Alta (7.8)0.07%—2 mar 2026
Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs.
CVE-2025-47384Media (6.5)0.11%—2 mar 2026
Transient DOS when MAC configures config id greater than supported maximum value.
CVE-2025-47383Alta (7.2)0.14%—2 mar 2026
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
CVE-2025-47379Alta (7.8)0.07%—2 mar 2026
Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources.
CVE-2025-47378Alta (7.1)0.07%—2 mar 2026
Cryptographic Issue when a shared VM reference allows HLOS to boot loader and access cert chain.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation93
  2. T1059 Command and Scripting Interpreter91
  3. T1190 Exploit Public-Facing Application29
  4. T1499.004 Application or System Exploitation12
  5. T1005 Data from Local System9
  6. T1499 Endpoint Denial of Service4

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm