« Back to list

Qualcomm

Qualcomm Ipq8071 Firmware: vulnerabilities and CVEs

Qualcomm Ipq8071 Firmware has 100 published vulnerabilities, 5 of them in the last 12 months. 13 are rated critical and 0 are listed by CISA as actively exploited.

CVEs100
Last 12 months5
Critical13
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-25275High (7.5)0.19%—Sep 17, 2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
CVE-2025-47339High (7.8)0.08%—Jan 7, 2026
Memory corruption while deinitializing a HDCP session.
CVE-2025-47325Medium (5.5)0.08%—Dec 18, 2025
Information disclosure while processing system calls with invalid parameters.
CVE-2025-27074High (7.8)0.08%—Nov 4, 2025
Memory corruption while processing a GP command response.
CVE-2025-27040Medium (6.5)0.08%—Oct 9, 2025
Information disclosure may occur while processing the hypervisor log.
CVE-2025-21482High (7.1)0.08%—Sep 24, 2025
Cryptographic issue while performing RSA PKCS padding decoding.
CVE-2025-27066High (7.5)0.28%—Aug 6, 2025
Transient DOS while processing an ANQP message.
CVE-2024-33056High (7.8)0.10%—Dec 2, 2024
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
CVE-2024-21473Critical (9.8)0.66%—Apr 1, 2024
Memory corruption while redirecting log file to any file location with any file name.
CVE-2023-33105High (7.5)0.75%—Mar 4, 2024
Transient DOS in WLAN Host and Firmware when large number of open authentication frames are sent with an invalid transaction sequence number.
CVE-2023-43536High (7.5)0.32%—Feb 6, 2024
Transient DOS while parse fils IE with length equal to 1.
CVE-2023-28569Medium (5.5)0.14%—Nov 7, 2023
Information disclosure in WLAN HAL while handling command through WMI interfaces.
CVE-2023-28563Medium (5.5)0.14%—Nov 7, 2023
Information disclosure in IOE Firmware while handling WMI command.
CVE-2023-28573High (7.8)0.12%—Sep 5, 2023
Memory corruption in WLAN HAL while parsing WMI command parameters.
CVE-2023-28567High (7.8)0.12%—Sep 5, 2023
Memory corruption in WLAN HAL while handling command through WMI interfaces.
CVE-2023-28565High (7.8)0.12%—Sep 5, 2023
Memory corruption in WLAN HAL while handling command streams through WMI interfaces.
CVE-2023-28564High (7.8)0.12%—Sep 5, 2023
Memory corruption in WLAN HAL while passing command parameters through WMI interfaces.
CVE-2023-28560High (7.8)0.12%—Sep 5, 2023
Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload.
CVE-2023-28559High (7.8)0.12%—Sep 5, 2023
Memory corruption in WLAN FW while processing command parameters from untrusted WMI payload.
CVE-2023-28549High (7.8)0.12%—Sep 5, 2023
Memory corruption in WLAN HAL while parsing Rx buffer in processing TLV payload.
CVE-2023-28544High (7.8)0.12%—Sep 5, 2023
Memory corruption in WLAN while sending transmit command from HLOS to UTF handlers.
CVE-2022-33275High (7.8)0.12%—Sep 5, 2023
Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range.
CVE-2023-21628High (7.8)0.12%—Jun 6, 2023
Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command.
CVE-2022-22076Medium (5.5)0.11%—Jun 6, 2023
information disclosure due to cryptographic issue in Core during RPMB read request.
CVE-2022-40531High (7.8)0.12%—Mar 10, 2023
Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message.
CVE-2022-40530High (7.8)0.13%—Mar 10, 2023
Memory corruption in WLAN due to integer overflow to buffer overflow in WLAN during initialization phase.
CVE-2022-25655High (7.8)0.12%—Mar 10, 2023
Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload.
CVE-2022-40512High (7.5)0.42%—Feb 12, 2023
Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon.
CVE-2022-33277High (7.8)0.12%—Feb 12, 2023
Memory corruption in modem due to buffer copy without checking size of input while receiving WMI command.
CVE-2022-33286Medium (6.5)0.38%—Jan 9, 2023
Transient DOS due to buffer over-read in WLAN while processing 802.11 management frames.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1068 Exploitation for Privilege Escalation4
  2. T1059 Command and Scripting Interpreter2
  3. T1190 Exploit Public-Facing Application2
  4. T1499 Endpoint Denial of Service2
  5. T1552.001 Credentials In Files1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Qualcomm