« Back to list

Qualcomm

Qualcomm Qcn6112 Firmware: vulnerabilities and CVEs

Qualcomm Qcn6112 Firmware has 130 published vulnerabilities, 8 of them in the last 12 months. 15 are rated critical and 0 are listed by CISA as actively exploited.

CVEs130
Last 12 months8
Critical15
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-25268High (8.8)0.11%—Jul 6, 2026
Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.
CVE-2025-59609Medium (5.5)0.09%—Jun 1, 2026
Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.
CVE-2025-47339High (7.8)0.08%—Jan 7, 2026
Memory corruption while deinitializing a HDCP session.
CVE-2025-47331Medium (6.1)0.08%—Jan 7, 2026
Information disclosure while processing a firmware event.
CVE-2025-27074High (7.8)0.08%—Nov 4, 2025
Memory corruption while processing a GP command response.
CVE-2025-27060High (8.8)0.09%—Oct 9, 2025
Memory corruption while performing SCM call with malformed inputs.
CVE-2025-27040Medium (6.5)0.08%—Oct 9, 2025
Information disclosure may occur while processing the hypervisor log.
CVE-2025-27059High (8.8)0.09%—Oct 9, 2025
Memory corruption while performing SCM call.
CVE-2025-47326High (7.5)0.24%—Sep 24, 2025
Transient DOS while handling command data during power control processing.
CVE-2025-47318High (7.5)0.21%—Sep 24, 2025
Transient DOS while parsing the EPTM test control message to get the test pattern.
CVE-2025-27066High (7.5)0.28%—Aug 6, 2025
Transient DOS while processing an ANQP message.
CVE-2025-27061High (7.8)0.09%—Jul 8, 2025
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
CVE-2025-27057High (7.5)0.23%—Jul 8, 2025
Transient DOS while handling beacon frames with invalid IE header length.
CVE-2025-27042High (7.8)0.09%—Jul 8, 2025
Memory corruption while processing video packets received from video firmware.
CVE-2025-21446High (7.5)0.22%—Jul 8, 2025
Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.
CVE-2025-21463High (7.5)0.23%—Jun 3, 2025
Transient DOS while processing the EHT operation IE in the received beacon frame.
CVE-2025-21448High (7.5)0.26%—Apr 7, 2025
Transient DOS may occur while parsing SSID in action frames.
CVE-2025-21435High (7.5)0.26%—Apr 7, 2025
Transient DOS may occur while parsing extended IE in beacon.
CVE-2024-43057High (7.8)0.12%—Mar 3, 2025
Memory corruption while processing command in Glink linux.
CVE-2024-49839Critical (9.8)0.29%—Feb 3, 2025
Memory corruption during management frame processing due to mismatch in T2LM info element.
CVE-2024-45571High (7.8)0.10%—Feb 3, 2025
Memory corruption may occour occur when stopping the WLAN interface after processing a WMI command from the interface.
CVE-2024-45569Critical (9.8)0.58%—Feb 3, 2025
Memory corruption while parsing the ML IE due to invalid frame content.
CVE-2024-45558High (7.5)0.36%—Jan 6, 2025
Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.
CVE-2024-38408Critical (9.1)0.14%—Nov 4, 2024
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
CVE-2024-33073High (8.2)0.35%—Oct 7, 2024
Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
CVE-2024-33066Critical (9.8)0.60%—Oct 7, 2024
Memory corruption while redirecting log file to any file location with any file name.
CVE-2024-33049High (7.5)0.32%—Oct 7, 2024
Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.
CVE-2024-33057High (7.5)0.30%—Sep 2, 2024
Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location.
CVE-2024-33050High (7.5)0.30%—Sep 2, 2024
Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper.
CVE-2024-33048High (7.5)0.30%—Sep 2, 2024
Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application15
  2. T1059 Command and Scripting Interpreter11
  3. T1068 Exploitation for Privilege Escalation10
  4. T1499.004 Application or System Exploitation7
  5. T1499 Endpoint Denial of Service3
  6. T1005 Data from Local System1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Qualcomm