« Back to list

Qualcomm

Qualcomm Netrani Firmware: vulnerabilities and CVEs

Qualcomm Netrani Firmware has 38 published vulnerabilities, 38 of them in the last 12 months. 1 are rated critical and 1 are listed by CISA as actively exploited.

CVEs38
Last 12 months38
Critical1
Actively exploited1

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-21385High (7.8)1.3%⚠ Active exploitationMar 2, 2026
Memory corruption while using alignments for memory allocation.

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-25275High (7.5)0.19%—Sep 17, 2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
CVE-2026-24081High (7.4)0.10%—Sep 17, 2026
Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
CVE-2026-25292High (7.6)0.15%—Aug 4, 2026
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
CVE-2026-25289Critical (9.6)0.19%—Aug 4, 2026
Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.
CVE-2026-24084High (7.5)0.25%—Aug 4, 2026
Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
CVE-2026-24079High (8.1)0.21%—Aug 4, 2026
Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
CVE-2026-24078Medium (6.5)0.17%—Aug 4, 2026
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
CVE-2026-24077Medium (6.5)0.17%—Aug 4, 2026
Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
CVE-2026-21384Medium (5.3)0.08%—Jul 6, 2026
Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits.
CVE-2026-21370Medium (5.3)0.08%—Jul 6, 2026
Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values.
CVE-2026-21368Medium (5.3)0.08%—Jul 6, 2026
Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks.
CVE-2026-24092High (7.2)0.10%—Jun 1, 2026
Memory Corruption when processing fastboot commands to set display mode.
CVE-2026-24091High (7.2)0.10%—Jun 1, 2026
Memory corruption while processing fastboot commands with improperly formatted input.
CVE-2026-24090High (7.1)0.06%—Jun 1, 2026
Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow.
CVE-2026-24089High (7.2)0.10%—Jun 1, 2026
Memory corruption while processing fastboot commands with invalid input.
CVE-2026-24088High (8.2)0.07%—Jun 1, 2026
Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
CVE-2026-24087High (7.2)0.10%—Jun 1, 2026
Memory corruption while processing fastboot OEM commands.
CVE-2026-24085High (7.2)0.10%—Jun 1, 2026
Memory Corruption when processing display command line information due to improper initialization of a variable.
CVE-2025-59610Medium (6.4)0.06%—Jun 1, 2026
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
CVE-2025-59606High (7.8)0.07%—Jun 1, 2026
Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization.
CVE-2025-59605High (7.8)0.07%—Jun 1, 2026
Memory Corruption when processing device identifier strings that exceed the expected maximum length.
CVE-2025-59604High (7.8)0.07%—Jun 1, 2026
Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.
CVE-2025-47407High (7)0.05%—May 4, 2026
Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level.
CVE-2025-47403High (7.5)0.22%—May 4, 2026
Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
CVE-2025-47401High (7.5)0.22%—May 4, 2026
Transient DOS when processing target power rate tables during channel configuration.
CVE-2026-21381High (7.5)0.15%—Apr 6, 2026
Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection.
CVE-2026-21367High (7.5)0.20%—Apr 6, 2026
Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.
CVE-2025-47392High (8.8)0.17%—Apr 6, 2026
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
CVE-2025-47391High (7.8)0.10%—Apr 6, 2026
Memory corruption while processing a frame request from user.
CVE-2025-47389High (7.8)0.10%—Apr 6, 2026
Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter18
  2. T1068 Exploitation for Privilege Escalation16
  3. T1091 Replication Through Removable Media6
  4. T1190 Exploit Public-Facing Application6
  5. T1210 Exploitation of Remote Services5
  6. T1499.004 Application or System Exploitation5

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Qualcomm