Qualcomm
Qualcomm Qcn5550 Firmware: vulnerabilidades y CVE
Qualcomm Qcn5550 Firmware tiene 81 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 14 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE81
Últimos 12 meses4
Críticas14
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-25275 | Alta (7.5) | 0.19% | — | 17 sept 2026 | Transient DOS when processing authentication frames with invalid FILS information element header lengths. |
| CVE-2025-47325 | Media (5.5) | 0.08% | — | 18 dic 2025 | Information disclosure while processing system calls with invalid parameters. |
| CVE-2025-27074 | Alta (7.8) | 0.08% | — | 4 nov 2025 | Memory corruption while processing a GP command response. |
| CVE-2025-27040 | Media (6.5) | 0.08% | — | 9 oct 2025 | Information disclosure may occur while processing the hypervisor log. |
| CVE-2024-21473 | Crítica (9.8) | 0.66% | — | 1 abr 2024 | Memory corruption while redirecting log file to any file location with any file name. |
| CVE-2023-33105 | Alta (7.5) | 0.75% | — | 4 mar 2024 | Transient DOS in WLAN Host and Firmware when large number of open authentication frames are sent with an invalid transaction sequence number. |
| CVE-2023-28569 | Media (5.5) | 0.14% | — | 7 nov 2023 | Information disclosure in WLAN HAL while handling command through WMI interfaces. |
| CVE-2023-28563 | Media (5.5) | 0.14% | — | 7 nov 2023 | Information disclosure in IOE Firmware while handling WMI command. |
| CVE-2023-28567 | Alta (7.8) | 0.12% | — | 5 sept 2023 | Memory corruption in WLAN HAL while handling command through WMI interfaces. |
| CVE-2023-28565 | Alta (7.8) | 0.12% | — | 5 sept 2023 | Memory corruption in WLAN HAL while handling command streams through WMI interfaces. |
| CVE-2023-28564 | Alta (7.8) | 0.12% | — | 5 sept 2023 | Memory corruption in WLAN HAL while passing command parameters through WMI interfaces. |
| CVE-2023-28560 | Alta (7.8) | 0.12% | — | 5 sept 2023 | Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload. |
| CVE-2023-28559 | Alta (7.8) | 0.12% | — | 5 sept 2023 | Memory corruption in WLAN FW while processing command parameters from untrusted WMI payload. |
| CVE-2023-28549 | Alta (7.8) | 0.12% | — | 5 sept 2023 | Memory corruption in WLAN HAL while parsing Rx buffer in processing TLV payload. |
| CVE-2023-28544 | Alta (7.8) | 0.12% | — | 5 sept 2023 | Memory corruption in WLAN while sending transmit command from HLOS to UTF handlers. |
| CVE-2023-21628 | Alta (7.8) | 0.12% | — | 6 jun 2023 | Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command. |
| CVE-2022-22076 | Media (5.5) | 0.11% | — | 6 jun 2023 | information disclosure due to cryptographic issue in Core during RPMB read request. |
| CVE-2022-25655 | Alta (7.8) | 0.12% | — | 10 mar 2023 | Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload. |
| CVE-2022-33238 | Alta (7.5) | 0.42% | — | 13 dic 2022 | Transient DOS due to loop with unreachable exit condition in WLAN while processing an incoming FTM frames. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity,… |
| CVE-2022-25652 | Alta (7.8) | 0.11% | — | 16 sept 2022 | Cryptographic issues in BSP due to improper hash verification in Snapdragon Wired Infrastructure and Networking |
| CVE-2021-35104 | Crítica (9.8) | 0.81% | — | 14 jun 2022 | Possible buffer overflow due to improper parsing of headers while playing the FLAC audio clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2021-35071 | Media (5.5) | 0.13% | — | 14 jun 2022 | Possible buffer over read due to lack of size validation while copying data from DBR buffer to RX buffer and can lead to Denial of Service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon… |
| CVE-2021-35088 | Crítica (9.1) | 0.85% | — | 1 abr 2022 | Possible out of bound read due to improper validation of IE length during SSID IE parse when channel is DFS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial… |
| CVE-2021-35069 | Alta (7.8) | 0.18% | — | 11 feb 2022 | Improper validation of data length received from DMA buffer can lead to memory corruption. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon… |
| CVE-2021-30325 | Media (6.7) | 0.14% | — | 11 feb 2022 | Possible out of bound access of DCI resources due to lack of validation process and resource allocation in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,… |
| CVE-2021-30324 | Media (6.7) | 0.14% | — | 11 feb 2022 | Possible out of bound write due to lack of boundary check for the maximum size of buffer when sending a DCI packet to remote process in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial… |
| CVE-2021-30313 | Media (6.4) | 0.10% | — | 13 ene 2022 | Use after free condition can occur in wired connectivity due to a race condition while creating and deleting folders in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon… |
| CVE-2021-30351 | Crítica (9.8) | 4.0% | — | 3 ene 2022 | An out of bound memory access can occur due to improper validation of number of frames being passed during music playback in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,… |
| CVE-2021-30337 | Alta (7.8) | 0.15% | — | 3 ene 2022 | Possible use after free when process shell memory is freed using IOCTL call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon… |
| CVE-2021-30335 | Alta (7.8) | 0.15% | — | 3 ene 2022 | Possible assertion in QOS request due to improper validation when multiple add or update request are received simultaneously in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.