Qualcomm
Qualcomm Qcn9022 Firmware: vulnerabilities and CVEs
Qualcomm Qcn9022 Firmware has 241 published vulnerabilities, 13 of them in the last 12 months. 25 are rated critical and 1 are listed by CISA as actively exploited.
CVEs241
Last 12 months13
Critical25
Actively exploited1
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-33063 | High (7.8) | 0.57% | ⚠ Active exploitation | Dec 5, 2023 | Memory corruption in DSP Services during a remote call from HLOS to DSP. |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25275 | High (7.5) | 0.19% | — | Sep 17, 2026 | Transient DOS when processing authentication frames with invalid FILS information element header lengths. |
| CVE-2026-25268 | High (8.8) | 0.11% | — | Jul 6, 2026 | Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations. |
| CVE-2026-24088 | High (8.2) | 0.07% | — | Jun 1, 2026 | Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader. |
| CVE-2025-59609 | Medium (5.5) | 0.09% | — | Jun 1, 2026 | Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length. |
| CVE-2025-47403 | High (7.5) | 0.22% | — | May 4, 2026 | Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming. |
| CVE-2026-21367 | High (7.5) | 0.20% | — | Apr 6, 2026 | Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans. |
| CVE-2025-47339 | High (7.8) | 0.08% | — | Jan 7, 2026 | Memory corruption while deinitializing a HDCP session. |
| CVE-2025-47331 | Medium (6.1) | 0.08% | — | Jan 7, 2026 | Information disclosure while processing a firmware event. |
| CVE-2025-47325 | Medium (5.5) | 0.08% | — | Dec 18, 2025 | Information disclosure while processing system calls with invalid parameters. |
| CVE-2025-27074 | High (7.8) | 0.08% | — | Nov 4, 2025 | Memory corruption while processing a GP command response. |
| CVE-2025-27060 | High (8.8) | 0.09% | — | Oct 9, 2025 | Memory corruption while performing SCM call with malformed inputs. |
| CVE-2025-27040 | Medium (6.5) | 0.08% | — | Oct 9, 2025 | Information disclosure may occur while processing the hypervisor log. |
| CVE-2025-27059 | High (8.8) | 0.09% | — | Oct 9, 2025 | Memory corruption while performing SCM call. |
| CVE-2025-47326 | High (7.5) | 0.24% | — | Sep 24, 2025 | Transient DOS while handling command data during power control processing. |
| CVE-2025-47318 | High (7.5) | 0.21% | — | Sep 24, 2025 | Transient DOS while parsing the EPTM test control message to get the test pattern. |
| CVE-2025-27073 | High (7.5) | 0.21% | — | Aug 6, 2025 | Transient DOS while creating NDP instance. |
| CVE-2025-27066 | High (7.5) | 0.28% | — | Aug 6, 2025 | Transient DOS while processing an ANQP message. |
| CVE-2025-21465 | Medium (6.5) | 0.09% | — | Aug 6, 2025 | Information disclosure while processing the hash segment in an MBN file. |
| CVE-2025-21464 | Medium (6.5) | 0.09% | — | Aug 6, 2025 | Information disclosure while reading data from an image using specified offset and size parameters. |
| CVE-2025-27057 | High (7.5) | 0.23% | — | Jul 8, 2025 | Transient DOS while handling beacon frames with invalid IE header length. |
| CVE-2025-21446 | High (7.5) | 0.22% | — | Jul 8, 2025 | Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests. |
| CVE-2025-21463 | High (7.5) | 0.23% | — | Jun 3, 2025 | Transient DOS while processing the EHT operation IE in the received beacon frame. |
| CVE-2025-21448 | High (7.5) | 0.26% | — | Apr 7, 2025 | Transient DOS may occur while parsing SSID in action frames. |
| CVE-2025-21435 | High (7.5) | 0.26% | — | Apr 7, 2025 | Transient DOS may occur while parsing extended IE in beacon. |
| CVE-2024-43046 | Medium (5.5) | 0.11% | — | Apr 7, 2025 | There may be information disclosure during memory re-allocation in TZ Secure OS. |
| CVE-2024-43057 | High (7.8) | 0.12% | — | Mar 3, 2025 | Memory corruption while processing command in Glink linux. |
| CVE-2024-49839 | Critical (9.8) | 0.29% | — | Feb 3, 2025 | Memory corruption during management frame processing due to mismatch in T2LM info element. |
| CVE-2024-45571 | High (7.8) | 0.10% | — | Feb 3, 2025 | Memory corruption may occour occur when stopping the WLAN interface after processing a WMI command from the interface. |
| CVE-2024-45569 | Critical (9.8) | 0.58% | — | Feb 3, 2025 | Memory corruption while parsing the ML IE due to invalid frame content. |
| CVE-2024-45558 | High (7.5) | 0.36% | — | Jan 6, 2025 | Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.