Qualcomm
Qualcomm Qcn9072 Firmware: vulnerabilidades y CVE
Qualcomm Qcn9072 Firmware tiene 236 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 25 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE236
Últimos 12 meses7
Críticas25
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-33063 | Alta (7.8) | 0.57% | ⚠ Explotación activa | 5 dic 2023 | Memory corruption in DSP Services during a remote call from HLOS to DSP. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-47339 | Alta (7.8) | 0.08% | — | 7 ene 2026 | Memory corruption while deinitializing a HDCP session. |
| CVE-2025-47331 | Media (6.1) | 0.08% | — | 7 ene 2026 | Information disclosure while processing a firmware event. |
| CVE-2025-47325 | Media (5.5) | 0.08% | — | 18 dic 2025 | Information disclosure while processing system calls with invalid parameters. |
| CVE-2025-27074 | Alta (7.8) | 0.08% | — | 4 nov 2025 | Memory corruption while processing a GP command response. |
| CVE-2025-27060 | Alta (8.8) | 0.09% | — | 9 oct 2025 | Memory corruption while performing SCM call with malformed inputs. |
| CVE-2025-27040 | Media (6.5) | 0.08% | — | 9 oct 2025 | Information disclosure may occur while processing the hypervisor log. |
| CVE-2025-27059 | Alta (8.8) | 0.09% | — | 9 oct 2025 | Memory corruption while performing SCM call. |
| CVE-2025-47326 | Alta (7.5) | 0.24% | — | 24 sept 2025 | Transient DOS while handling command data during power control processing. |
| CVE-2025-47318 | Alta (7.5) | 0.21% | — | 24 sept 2025 | Transient DOS while parsing the EPTM test control message to get the test pattern. |
| CVE-2025-27073 | Alta (7.5) | 0.21% | — | 6 ago 2025 | Transient DOS while creating NDP instance. |
| CVE-2025-27066 | Alta (7.5) | 0.28% | — | 6 ago 2025 | Transient DOS while processing an ANQP message. |
| CVE-2025-21465 | Media (6.5) | 0.09% | — | 6 ago 2025 | Information disclosure while processing the hash segment in an MBN file. |
| CVE-2025-21464 | Media (6.5) | 0.09% | — | 6 ago 2025 | Information disclosure while reading data from an image using specified offset and size parameters. |
| CVE-2025-27061 | Alta (7.8) | 0.09% | — | 8 jul 2025 | Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware. |
| CVE-2025-27057 | Alta (7.5) | 0.23% | — | 8 jul 2025 | Transient DOS while handling beacon frames with invalid IE header length. |
| CVE-2025-27043 | Alta (7.8) | 0.09% | — | 8 jul 2025 | Memory corruption while processing manipulated payload in video firmware. |
| CVE-2025-27042 | Alta (7.8) | 0.09% | — | 8 jul 2025 | Memory corruption while processing video packets received from video firmware. |
| CVE-2025-21446 | Alta (7.5) | 0.22% | — | 8 jul 2025 | Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests. |
| CVE-2025-21463 | Alta (7.5) | 0.23% | — | 3 jun 2025 | Transient DOS while processing the EHT operation IE in the received beacon frame. |
| CVE-2025-21448 | Alta (7.5) | 0.26% | — | 7 abr 2025 | Transient DOS may occur while parsing SSID in action frames. |
| CVE-2025-21435 | Alta (7.5) | 0.26% | — | 7 abr 2025 | Transient DOS may occur while parsing extended IE in beacon. |
| CVE-2024-43046 | Media (5.5) | 0.11% | — | 7 abr 2025 | There may be information disclosure during memory re-allocation in TZ Secure OS. |
| CVE-2024-43057 | Alta (7.8) | 0.12% | — | 3 mar 2025 | Memory corruption while processing command in Glink linux. |
| CVE-2024-49839 | Crítica (9.8) | 0.29% | — | 3 feb 2025 | Memory corruption during management frame processing due to mismatch in T2LM info element. |
| CVE-2024-45571 | Alta (7.8) | 0.10% | — | 3 feb 2025 | Memory corruption may occour occur when stopping the WLAN interface after processing a WMI command from the interface. |
| CVE-2024-45569 | Crítica (9.8) | 0.58% | — | 3 feb 2025 | Memory corruption while parsing the ML IE due to invalid frame content. |
| CVE-2024-45558 | Alta (7.5) | 0.36% | — | 6 ene 2025 | Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length. |
| CVE-2024-38408 | Crítica (9.1) | 0.14% | — | 4 nov 2024 | Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions. |
| CVE-2024-33073 | Alta (8.2) | 0.35% | — | 7 oct 2024 | Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE. |
| CVE-2024-33066 | Crítica (9.8) | 0.60% | — | 7 oct 2024 | Memory corruption while redirecting log file to any file location with any file name. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.