← Back

Fastconnect 6900 Firmware

fastconnect_6900_firmware

Vendor: Qualcomm • 574 CVEs

CVEs (574)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qualcomm
190315 5g Firmware
Aqt1000 FirmwareAr8035 Firmware+187 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS in WLAN Firmware while interpreting MBSSID IE of a received beacon frame.
1Qualcomm
70Aqt1000 Firmware
Csrb31024 FirmwareFastconnect 6200 Firmware+67 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS in WLAN Host when a mobile station receives invalid channel in CSA IE while doing channel switch announcement (CSA).
1Qualcomm
25Fastconnect 6800 Firmware
Fastconnect 6900 FirmwareFastconnect 7800 Firmware+22 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Memory corruption in WLAN Firmware while parsing receieved GTK Keys in GTK KDE.
1Qualcomm
195315 5g Iot Firmware
Aqt1000 FirmwareAr8035 Firmware+192 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN HAL while parsing WMI command parameters.
1Qualcomm
285315 5g Iot Firmware
Aqt1000 FirmwareAr8031 Firmware+282 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN HAL while handling command through WMI interfaces.
1Qualcomm
2929205 Lte Firmware
Apq8017 FirmwareApq8064au Firmware+289 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN HAL while handling command streams through WMI interfaces.
1Qualcomm
247Aqt1000 Firmware
Ar8031 FirmwareAr9380 Firmware+244 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN HAL while passing command parameters through WMI interfaces.
1Qualcomm
211Aqt1000 Firmware
Ar8031 FirmwareAr9380 Firmware+208 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN FW while processing command parameters from untrusted WMI payload.
1Qualcomm
195315 5g Iot Modem Firmware
Aqt1000 FirmwareAr8031 Firmware+192 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN handler while processing PhyID in Tx status handler.
1Qualcomm
273315 5g Iot Modem Firmware
Aqt1000 FirmwareAr8031 Firmware+270 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN HAL while processing command parameters from untrusted WMI payload.
1Qualcomm
220315 5g Iot Modem Firmware
Aqt1000 FirmwareAr8035 Firmware+217 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN HAL while parsing Rx buffer in processing TLV payload.
1Qualcomm
179Aqt1000 Firmware
Ar8035 FirmwareAr9380 Firmware+176 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN HAL while processing Tx/Rx commands from QDART.
1Qualcomm
205Aqt1000 Firmware
Ar9380 FirmwareCsr8811 Firmware+202 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN while sending transmit command from HLOS to UTF handlers.
1Qualcomm
130Aqt1000 Firmware
Csra6620 FirmwareCsra6640 Firmware+127 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region.
1Qualcomm
30Fastconnect 6800 Firmware
Fastconnect 6900 FirmwareFastconnect 7800 Firmware+27 more
Nov 21, 2024
Aug 8, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In the function call related to CAM_REQ_MGR_RELEASE_BUF there is no check if the buffer is being used. So when a function called cam_mem_get_cpu_buf to get the kernel va to use, another thread can call CAM_REQ_MGR_RELEAS...Show more
In the function call related to CAM_REQ_MGR_RELEASE_BUF there is no check if the buffer is being used. So when a function called cam_mem_get_cpu_buf to get the kernel va to use, another thread can call CAM_REQ_MGR_RELEASE_BUF to unmap the kernel va which cause UAF of the kernel address.Show less
1Qualcomm
30Fastconnect 6800 Firmware
Fastconnect 6900 FirmwareFastconnect 7800 Firmware+27 more
Nov 21, 2024
Aug 8, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it. In other words, user mode may race and modify the packet header (e.g. header.count), caus...Show more
The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it. In other words, user mode may race and modify the packet header (e.g. header.count), causing checks (e.g. size checks) in kernel code to be invalid. This may lead to out-of-bounds read/write issues.Show less
1Qualcomm
59205 Firmware
215 FirmwareAqt1000 Firmware+56 more
Nov 21, 2024
Aug 8, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it.
1Qualcomm
183315 5g Iot Firmware
Apq8064au FirmwareAqt1000 Firmware+180 more
Aug 11, 2025
Jul 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption in WLAN HOST while fetching TX status information.
1Qualcomm
198Aqt1000 Firmware
Ar8031 FirmwareAr9380 Firmware+195 more
Aug 11, 2025
Jul 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption in Data Modem while processing DMA buffer release event about CFR data.
1Qualcomm
158215 Firmware
Ar8035 FirmwareCsra6620 Firmware+155 more
Aug 11, 2025
Jul 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption in WLAN HOST while parsing QMI WLAN Firmware response message.