Qualcomm
Qualcomm Xg101002 Firmware: vulnerabilities and CVEs
Qualcomm Xg101002 Firmware has 54 published vulnerabilities, 54 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs54
Last 12 months54
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25289 | Critical (9.6) | 0.19% | — | Aug 4, 2026 | Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values. |
| CVE-2026-25288 | High (7.4) | 0.16% | — | Aug 4, 2026 | Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size. |
| CVE-2026-24080 | High (7.8) | 0.10% | — | Aug 4, 2026 | Memory Corruption when handling malformed request parameters in the fingerprint TA. |
| CVE-2026-24076 | Medium (6.7) | 0.11% | — | Aug 4, 2026 | Memory Corruption when processing registry values with incorrect types using a direct query method. |
| CVE-2026-25271 | High (7) | 0.07% | — | Jul 6, 2026 | Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use. |
| CVE-2026-21379 | High (7.8) | 0.10% | — | Jul 6, 2026 | Memory Corruption when allocating memory with sizes that exceed the maximum allowed value. |
| CVE-2026-25260 | High (7) | 0.05% | — | Jun 1, 2026 | Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications. |
| CVE-2026-25259 | High (7.8) | 0.07% | — | Jun 1, 2026 | Memory corruption while processing multiple IOCTL command for escape operations. |
| CVE-2026-25258 | High (7.8) | 0.07% | — | Jun 1, 2026 | Memory corruption while processing IOCTL calls for escape operations. |
| CVE-2025-59614 | Medium (6.7) | 0.08% | — | Jun 1, 2026 | Memory Corruption when sending random number generator command with insufficient output buffer size. |
| CVE-2025-59613 | Medium (6.7) | 0.08% | — | Jun 1, 2026 | Memory Corruption when output buffer size is smaller than input buffer size during data copying operation. |
| CVE-2025-59612 | Medium (6.7) | 0.08% | — | Jun 1, 2026 | Memory corruption in windows drivers while sending incorrect trusted application request |
| CVE-2025-59611 | Medium (6.7) | 0.08% | — | Jun 1, 2026 | Memory corruption in diagnostic services due to absence of input validation |
| CVE-2025-59606 | High (7.8) | 0.07% | — | Jun 1, 2026 | Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization. |
| CVE-2025-59604 | High (7.8) | 0.07% | — | Jun 1, 2026 | Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer. |
| CVE-2026-25266 | High (7.8) | 0.07% | — | May 4, 2026 | Memory corruption while processing IOCTL command when device is in power-save state. |
| CVE-2025-47406 | Medium (5.5) | 0.07% | — | May 4, 2026 | Information Disclosure while processing IOCTL handler callbacks without verifying buffer size. |
| CVE-2025-47403 | High (7.5) | 0.22% | — | May 4, 2026 | Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming. |
| CVE-2025-47401 | High (7.5) | 0.22% | — | May 4, 2026 | Transient DOS when processing target power rate tables during channel configuration. |
| CVE-2026-21382 | High (7.8) | 0.07% | — | Apr 6, 2026 | Memory Corruption when handling power management requests with improperly sized input/output buffers. |
| CVE-2026-21381 | High (7.5) | 0.15% | — | Apr 6, 2026 | Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection. |
| CVE-2026-21380 | High (7.8) | 0.07% | — | Apr 6, 2026 | Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory. |
| CVE-2026-21378 | High (7.8) | 0.07% | — | Apr 6, 2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver. |
| CVE-2026-21376 | High (7.8) | 0.10% | — | Apr 6, 2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver. |
| CVE-2026-21375 | High (7.8) | 0.07% | — | Apr 6, 2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing. |
| CVE-2026-21374 | High (7.8) | 0.11% | — | Apr 6, 2026 | Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validation. |
| CVE-2026-21373 | High (7.8) | 0.08% | — | Apr 6, 2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing. |
| CVE-2026-21372 | High (7.8) | 0.10% | — | Apr 6, 2026 | Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations. |
| CVE-2026-21371 | High (7.8) | 0.10% | — | Apr 6, 2026 | Memory Corruption when retrieving output buffer with insufficient size validation. |
| CVE-2026-21367 | High (7.5) | 0.20% | — | Apr 6, 2026 | Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.