CVEs (191)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 135Ar8035 Firmware Csrb31024 FirmwareFastconnect 6700 Firmware+132 moreNov 5, 2025 Nov 4, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan. |
1Qualcomm 202Apq8017 Firmware Apq8064au FirmwareAqt1000 Firmware+199 moreNov 28, 2025 Sep 24, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing the EPTM test control message to get the test pattern. |
1Qualcomm 370315 5g Iot Modem Firmware Aqt1000 FirmwareAr8031 Firmware+367 moreNov 28, 2025 Aug 6, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while processing an ANQP message. |
1Qualcomm 25Fastconnect 6700 Firmware Fastconnect 6900 FirmwareQca6595au Firmware+22 moreJan 30, 2026 Apr 7, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption may occur while reading board data via IOCTL call when the WLAN driver copies the content to the provided output buffer. |
1Qualcomm 43Fastconnect 6200 Firmware Fastconnect 6700 FirmwareFastconnect 6900 Firmware+40 moreOct 3, 2025 Apr 7, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while IOCTL call is invoked from user-space to read board data. |
1Qualcomm 51Aqt1000 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+48 moreAug 11, 2025 Jan 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver. |
1Qualcomm 51Aqt1000 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+48 moreAug 11, 2025 Jan 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when IOCTL call is invoked from user-space to read board data. |
1Qualcomm 54Aqt1000 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+51 moreDec 12, 2024 Dec 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver. |
1Qualcomm 229315 5g Iot Modem Firmware Aqt1000 FirmwareAr8035 Firmware+226 moreNov 8, 2024 Nov 4, 2024 N/A· v4 9.1 CRITICAL· v3 N/A· v2 Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions. |
1Qualcomm 282315 5g Iot Firmware 9206 Lte FirmwareApq8017 Firmware+279 moreAug 11, 2025 Sep 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while processing TIM IE from beacon frame as there is no check for IE length. |
1Qualcomm 303315 5g Iot Modem Firmware Aqt1000 FirmwareAr8031 Firmware+300 moreAug 11, 2025 Feb 6, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parse fils IE with length equal to 1. |
1Qualcomm 350315 5g Iot Modem Firmware 9206 Lte Modem FirmwareApq8017 Firmware+347 moreAug 11, 2025 Jan 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. |
1Qualcomm 304315 5g Iot Modem Firmware Aqt1000 FirmwareAr8031 Firmware+301 moreAug 11, 2025 Jan 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host. |
1Qualcomm 284315 5g Iot Modem Firmware Aqt1000 FirmwareAr8031 Firmware+281 moreAug 11, 2025 Jan 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS in WLAN Firmware while parsing a BTM request. |
1Qualcomm 257315 5g Iot Modem Firmware Aqt1000 FirmwareAr8031 Firmware+254 moreAug 11, 2025 Dec 5, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing WPA IES, when it is passed with length more than expected size. |
1Qualcomm 300315 5g Iot Modem Firmware Aqt1000 FirmwareAr8031 Firmware+297 moreAug 11, 2025 Dec 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when processing cmd parameters while parsing vdev. |
1Qualcomm 365315 5g Iot Modem Firmware 8098 Firmware8998 Firmware+362 moreAug 11, 2025 Dec 5, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame. |
1Qualcomm 184315 5g Iot Modem Firmware Aqt1000 FirmwareAr8031 Firmware+181 moreAug 11, 2025 Dec 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in BT controller while parsing debug commands with specific sub-opcodes at HCI interface level. |
1Qualcomm 307315 5g Iot Modem Firmware 9205 Lte Modem FirmwareAqt1000 Firmware+304 moreAug 11, 2025 Dec 5, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE. |
1Qualcomm 329315 5g Iot Modem Firmware 9205 Lte Modem Firmware9206 Lte Modem Firmware+326 moreAug 11, 2025 Dec 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in MPP performance while accessing DSM watermark using external memory address. |