Qualcomm
Qualcomm Ipq4018 Firmware: vulnerabilities and CVEs
Qualcomm Ipq4018 Firmware has 116 published vulnerabilities, 2 of them in the last 12 months. 14 are rated critical and 1 are listed by CISA as actively exploited.
CVEs116
Last 12 months2
Critical14
Actively exploited1
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-33063 | High (7.8) | 0.69% | ⚠ Active exploitation | Dec 5, 2023 | Memory corruption in DSP Services during a remote call from HLOS to DSP. |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24088 | High (8.2) | 0.07% | — | Jun 1, 2026 | Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader. |
| CVE-2025-47339 | High (7.8) | 0.08% | — | Jan 7, 2026 | Memory corruption while deinitializing a HDCP session. |
| CVE-2025-21482 | High (7.1) | 0.08% | — | Sep 24, 2025 | Cryptographic issue while performing RSA PKCS padding decoding. |
| CVE-2025-27066 | High (7.5) | 0.28% | — | Aug 6, 2025 | Transient DOS while processing an ANQP message. |
| CVE-2024-33050 | High (7.5) | 0.30% | — | Sep 2, 2024 | Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper. |
| CVE-2024-33014 | High (7.5) | 0.32% | — | Aug 5, 2024 | Transient DOS while parsing ESP IE from beacon/probe response frame. |
| CVE-2024-33012 | High (7.5) | 0.28% | — | Aug 5, 2024 | Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon. |
| CVE-2024-33011 | High (7.5) | 0.28% | — | Aug 5, 2024 | Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero. |
| CVE-2024-33010 | High (7.5) | 0.28% | — | Aug 5, 2024 | Transient DOS while parsing fragments of MBSSID IE from beacon frame. |
| CVE-2024-23368 | High (7.8) | 0.10% | — | Jul 1, 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition. |
| CVE-2024-21473 | Critical (9.8) | 0.66% | — | Apr 1, 2024 | Memory corruption while redirecting log file to any file location with any file name. |
| CVE-2023-33105 | High (7.5) | 0.75% | — | Mar 4, 2024 | Transient DOS in WLAN Host and Firmware when large number of open authentication frames are sent with an invalid transaction sequence number. |
| CVE-2023-43536 | High (7.5) | 0.32% | — | Feb 6, 2024 | Transient DOS while parse fils IE with length equal to 1. |
| CVE-2023-43511 | High (7.5) | 0.32% | — | Jan 2, 2024 | Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. |
| CVE-2023-33116 | High (7.5) | 0.32% | — | Jan 2, 2024 | Transient DOS while parsing ieee80211_parse_mscs_ie in WIN WLAN driver. |
| CVE-2023-33109 | High (7.5) | 0.34% | — | Jan 2, 2024 | Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host. |
| CVE-2023-33083 | Critical (9.8) | 0.61% | — | Dec 5, 2023 | Memory corruption in WLAN Host while processing RRM beacon on the AP. |
| CVE-2023-33082 | Critical (9.8) | 0.53% | — | Dec 5, 2023 | Memory corruption while sending an Assoc Request having BTM Query or BTM Response containing MBO IE. |
| CVE-2023-33080 | High (7.5) | 0.34% | — | Dec 5, 2023 | Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame. |
| CVE-2023-33063 | High (7.8) | 0.69% | ⚠ Active exploitation | Dec 5, 2023 | Memory corruption in DSP Services during a remote call from HLOS to DSP. |
| CVE-2023-28569 | Medium (5.5) | 0.14% | — | Nov 7, 2023 | Information disclosure in WLAN HAL while handling command through WMI interfaces. |
| CVE-2023-28563 | Medium (5.5) | 0.14% | — | Nov 7, 2023 | Information disclosure in IOE Firmware while handling WMI command. |
| CVE-2023-33027 | High (7.5) | 0.32% | — | Oct 3, 2023 | Transient DOS in WLAN Firmware while parsing rsn ies. |
| CVE-2023-33015 | High (7.5) | 0.38% | — | Sep 5, 2023 | Transient DOS in WLAN Firmware while interpreting MBSSID IE of a received beacon frame. |
| CVE-2023-28567 | High (7.8) | 0.12% | — | Sep 5, 2023 | Memory corruption in WLAN HAL while handling command through WMI interfaces. |
| CVE-2023-28565 | High (7.8) | 0.12% | — | Sep 5, 2023 | Memory corruption in WLAN HAL while handling command streams through WMI interfaces. |
| CVE-2023-28564 | High (7.8) | 0.12% | — | Sep 5, 2023 | Memory corruption in WLAN HAL while passing command parameters through WMI interfaces. |
| CVE-2023-28560 | High (7.8) | 0.12% | — | Sep 5, 2023 | Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload. |
| CVE-2023-28559 | High (7.8) | 0.12% | — | Sep 5, 2023 | Memory corruption in WLAN FW while processing command parameters from untrusted WMI payload. |
| CVE-2023-28558 | High (7.8) | 0.12% | — | Sep 5, 2023 | Memory corruption in WLAN handler while processing PhyID in Tx status handler. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.