« Back to list

Qualcomm

Qualcomm Xg101002 Firmware: vulnerabilities and CVEs

Qualcomm Xg101002 Firmware has 54 published vulnerabilities, 54 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs54
Last 12 months54
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-25289Critical (9.6)0.19%—Aug 4, 2026
Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.
CVE-2026-25288High (7.4)0.16%—Aug 4, 2026
Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
CVE-2026-24080High (7.8)0.10%—Aug 4, 2026
Memory Corruption when handling malformed request parameters in the fingerprint TA.
CVE-2026-24076Medium (6.7)0.11%—Aug 4, 2026
Memory Corruption when processing registry values with incorrect types using a direct query method.
CVE-2026-25271High (7)0.07%—Jul 6, 2026
Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use.
CVE-2026-21379High (7.8)0.10%—Jul 6, 2026
Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.
CVE-2026-25260High (7)0.05%—Jun 1, 2026
Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications.
CVE-2026-25259High (7.8)0.07%—Jun 1, 2026
Memory corruption while processing multiple IOCTL command for escape operations.
CVE-2026-25258High (7.8)0.07%—Jun 1, 2026
Memory corruption while processing IOCTL calls for escape operations.
CVE-2025-59614Medium (6.7)0.08%—Jun 1, 2026
Memory Corruption when sending random number generator command with insufficient output buffer size.
CVE-2025-59613Medium (6.7)0.08%—Jun 1, 2026
Memory Corruption when output buffer size is smaller than input buffer size during data copying operation.
CVE-2025-59612Medium (6.7)0.08%—Jun 1, 2026
Memory corruption in windows drivers while sending incorrect trusted application request
CVE-2025-59611Medium (6.7)0.08%—Jun 1, 2026
Memory corruption in diagnostic services due to absence of input validation
CVE-2025-59606High (7.8)0.07%—Jun 1, 2026
Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization.
CVE-2025-59604High (7.8)0.07%—Jun 1, 2026
Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.
CVE-2026-25266High (7.8)0.07%—May 4, 2026
Memory corruption while processing IOCTL command when device is in power-save state.
CVE-2025-47406Medium (5.5)0.07%—May 4, 2026
Information Disclosure while processing IOCTL handler callbacks without verifying buffer size.
CVE-2025-47403High (7.5)0.22%—May 4, 2026
Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
CVE-2025-47401High (7.5)0.22%—May 4, 2026
Transient DOS when processing target power rate tables during channel configuration.
CVE-2026-21382High (7.8)0.07%—Apr 6, 2026
Memory Corruption when handling power management requests with improperly sized input/output buffers.
CVE-2026-21381High (7.5)0.15%—Apr 6, 2026
Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection.
CVE-2026-21380High (7.8)0.07%—Apr 6, 2026
Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory.
CVE-2026-21378High (7.8)0.07%—Apr 6, 2026
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
CVE-2026-21376High (7.8)0.10%—Apr 6, 2026
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
CVE-2026-21375High (7.8)0.07%—Apr 6, 2026
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
CVE-2026-21374High (7.8)0.11%—Apr 6, 2026
Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validation.
CVE-2026-21373High (7.8)0.08%—Apr 6, 2026
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
CVE-2026-21372High (7.8)0.10%—Apr 6, 2026
Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations.
CVE-2026-21371High (7.8)0.10%—Apr 6, 2026
Memory Corruption when retrieving output buffer with insufficient size validation.
CVE-2026-21367High (7.5)0.20%—Apr 6, 2026
Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter39
  2. T1068 Exploitation for Privilege Escalation39
  3. T1499.004 Application or System Exploitation5
  4. T1190 Exploit Public-Facing Application4
  5. T1210 Exploitation of Remote Services2
  6. T1552.004 Private Keys1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Qualcomm