« Back to list

Qualcomm

Qualcomm Sw6100 Firmware: vulnerabilities and CVEs

Qualcomm Sw6100 Firmware has 10 published vulnerabilities, 10 of them in the last 12 months. 0 are rated critical and 1 are listed by CISA as actively exploited.

CVEs10
Last 12 months10
Critical0
Actively exploited1

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-21385High (7.8)1.3%⚠ Active exploitationMar 2, 2026
Memory corruption while using alignments for memory allocation.

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-24080High (7.8)0.10%—Aug 4, 2026
Memory Corruption when handling malformed request parameters in the fingerprint TA.
CVE-2026-24079High (8.1)0.21%—Aug 4, 2026
Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
CVE-2026-24078Medium (6.5)0.17%—Aug 4, 2026
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
CVE-2025-47400High (7.1)0.10%—Apr 6, 2026
Cryptographic issue while copying data to a destination buffer without validating its size.
CVE-2025-47392High (8.8)0.17%—Apr 6, 2026
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
CVE-2025-47389High (7.8)0.10%—Apr 6, 2026
Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
CVE-2026-21385High (7.8)1.3%⚠ Active exploitationMar 2, 2026
Memory corruption while using alignments for memory allocation.
CVE-2025-59600High (7.8)0.07%—Mar 2, 2026
Memory Corruption when adding user-supplied data without checking available buffer space.
CVE-2025-47383High (7.2)0.14%—Mar 2, 2026
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
CVE-2025-47373High (7.8)0.07%—Mar 2, 2026
Memory Corruption when accessing buffers with invalid length during TA invocation.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter6
  2. T1068 Exploitation for Privilege Escalation6
  3. T1210 Exploitation of Remote Services3
  4. T1005 Data from Local System1
  5. T1041 Exfiltration Over C2 Channel1
  6. T1078 Valid Accounts1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Qualcomm