« Back to list

Qualcomm

Qualcomm Sm4850p Firmware: vulnerabilities and CVEs

Qualcomm Sm4850p Firmware has 12 published vulnerabilities, 12 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs12
Last 12 months12
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-25275High (7.5)0.19%—Sep 17, 2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
CVE-2026-25292High (7.6)0.15%—Aug 4, 2026
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
CVE-2026-24092High (7.2)0.10%—Jun 1, 2026
Memory Corruption when processing fastboot commands to set display mode.
CVE-2026-24091High (7.2)0.10%—Jun 1, 2026
Memory corruption while processing fastboot commands with improperly formatted input.
CVE-2026-24090High (7.1)0.06%—Jun 1, 2026
Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow.
CVE-2026-24089High (7.2)0.10%—Jun 1, 2026
Memory corruption while processing fastboot commands with invalid input.
CVE-2026-24088High (8.2)0.07%—Jun 1, 2026
Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
CVE-2026-24087High (7.2)0.10%—Jun 1, 2026
Memory corruption while processing fastboot OEM commands.
CVE-2026-24085High (7.2)0.10%—Jun 1, 2026
Memory Corruption when processing display command line information due to improper initialization of a variable.
CVE-2025-59610Medium (6.4)0.06%—Jun 1, 2026
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
CVE-2025-59606High (7.8)0.07%—Jun 1, 2026
Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization.
CVE-2025-59604High (7.8)0.07%—Jun 1, 2026
Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter6
  2. T1068 Exploitation for Privilege Escalation6
  3. T1091 Replication Through Removable Media6
  4. T1190 Exploit Public-Facing Application1
  5. T1499 Endpoint Denial of Service1
  6. T1565.001 Stored Data Manipulation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Qualcomm