« Volver al listado

Qualcomm

Qualcomm Ipq8174 Firmware: vulnerabilidades y CVE

Qualcomm Ipq8174 Firmware tiene 219 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 27 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE219
Últimos 12 meses5
Críticas27
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-33063Alta (7.8)0.69%⚠ Explotación activa5 dic 2023
Memory corruption in DSP Services during a remote call from HLOS to DSP.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-47339Alta (7.8)0.08%—7 ene 2026
Memory corruption while deinitializing a HDCP session.
CVE-2025-47331Media (6.1)0.08%—7 ene 2026
Information disclosure while processing a firmware event.
CVE-2025-47325Media (5.5)0.08%—18 dic 2025
Information disclosure while processing system calls with invalid parameters.
CVE-2025-27074Alta (7.8)0.08%—4 nov 2025
Memory corruption while processing a GP command response.
CVE-2025-27040Media (6.5)0.08%—9 oct 2025
Information disclosure may occur while processing the hypervisor log.
CVE-2025-47326Alta (7.5)0.24%—24 sept 2025
Transient DOS while handling command data during power control processing.
CVE-2025-21482Alta (7.1)0.08%—24 sept 2025
Cryptographic issue while performing RSA PKCS padding decoding.
CVE-2025-27073Alta (7.5)0.21%—6 ago 2025
Transient DOS while creating NDP instance.
CVE-2025-27066Alta (7.5)0.28%—6 ago 2025
Transient DOS while processing an ANQP message.
CVE-2025-27061Alta (7.8)0.09%—8 jul 2025
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
CVE-2025-27057Alta (7.5)0.23%—8 jul 2025
Transient DOS while handling beacon frames with invalid IE header length.
CVE-2025-27043Alta (7.8)0.09%—8 jul 2025
Memory corruption while processing manipulated payload in video firmware.
CVE-2025-27042Alta (7.8)0.09%—8 jul 2025
Memory corruption while processing video packets received from video firmware.
CVE-2025-21446Alta (7.5)0.22%—8 jul 2025
Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.
CVE-2025-21463Alta (7.5)0.23%—3 jun 2025
Transient DOS while processing the EHT operation IE in the received beacon frame.
CVE-2025-21448Alta (7.5)0.26%—7 abr 2025
Transient DOS may occur while parsing SSID in action frames.
CVE-2025-21435Alta (7.5)0.26%—7 abr 2025
Transient DOS may occur while parsing extended IE in beacon.
CVE-2024-43057Alta (7.8)0.12%—3 mar 2025
Memory corruption while processing command in Glink linux.
CVE-2024-49839Crítica (9.8)0.29%—3 feb 2025
Memory corruption during management frame processing due to mismatch in T2LM info element.
CVE-2024-45571Alta (7.8)0.10%—3 feb 2025
Memory corruption may occour occur when stopping the WLAN interface after processing a WMI command from the interface.
CVE-2024-45569Crítica (9.8)0.58%—3 feb 2025
Memory corruption while parsing the ML IE due to invalid frame content.
CVE-2024-45558Alta (7.5)0.36%—6 ene 2025
Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.
CVE-2024-33056Alta (7.8)0.10%—2 dic 2024
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
CVE-2024-33073Alta (8.2)0.35%—7 oct 2024
Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
CVE-2024-33066Crítica (9.8)0.60%—7 oct 2024
Memory corruption while redirecting log file to any file location with any file name.
CVE-2024-33049Alta (7.5)0.32%—7 oct 2024
Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.
CVE-2024-33057Alta (7.5)0.30%—2 sept 2024
Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location.
CVE-2024-33050Alta (7.5)0.30%—2 sept 2024
Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper.
CVE-2024-33048Alta (7.5)0.30%—2 sept 2024
Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.
CVE-2024-33026Alta (7.5)0.28%—5 ago 2024
Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of timestamp.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application14
  2. T1068 Exploitation for Privilege Escalation11
  3. T1059 Command and Scripting Interpreter10
  4. T1499.004 Application or System Exploitation7
  5. T1499 Endpoint Denial of Service3
  6. T1005 Data from Local System1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm