← Back

Snapdragon X35 5g Modem Rf System Firmware

snapdragon_x35_5g_modem-rf_system_firmware

Vendor: Qualcomm • 94 CVEs

CVEs (94)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qualcomm
191Aqt1000 Firmware
Ar8035 FirmwareFastconnect 6200 Firmware+188 more
Nov 28, 2025
Jun 3, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption may occur while attaching VM when the HLOS retains access to VM.
1Qualcomm
267315 5g Iot Modem Firmware
Aqt1000 FirmwareAr8035 Firmware+264 more
Oct 6, 2025
Apr 7, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS may occur while parsing SSID in action frames.
1Qualcomm
223315 5g Iot Modem Firmware
Apq8017 FirmwareApq8064au Firmware+220 more
Oct 6, 2025
Apr 7, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
1Qualcomm
699206 Lte Modem Firmware
Apq8017 FirmwareAr8031 Firmware+66 more
Oct 6, 2025
Apr 7, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.
1Qualcomm
145Ar8035 Firmware
Fastconnect 6200 FirmwareFastconnect 6700 Firmware+142 more
Oct 6, 2025
Apr 7, 2025
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Memory corruption while processing multiple IOCTL calls from HLOS to DSP.
1Qualcomm
60Ar8035 Firmware
Fastconnect 6700 FirmwareFastconnect 6900 Firmware+57 more
Aug 19, 2025
Apr 7, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption can occur when TME processes addresses from TZ and MPSS requests without proper validation.
1Qualcomm
240Aqt1000 Firmware
Ar8035 FirmwareCsra6620 Firmware+237 more
Oct 6, 2025
Apr 7, 2025
N/A· v4
6.2 MEDIUM· v3
N/A· v2
Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass.
1Qualcomm
158Ar8035 Firmware
Fastconnect 6700 FirmwareFastconnect 6800 Firmware+155 more
Oct 6, 2025
Apr 7, 2025
N/A· v4
7.7 HIGH· v3
N/A· v2
Information disclosure while creating MQ channels.
1Qualcomm
164Ar8035 Firmware
Fastconnect 6200 FirmwareFastconnect 6700 Firmware+161 more
Oct 6, 2025
Apr 7, 2025
N/A· v4
7.1 HIGH· v3
N/A· v2
Cryptographic issues while generating an asymmetric key pair for RKP use cases.
1Qualcomm
308315 5g Iot Modem Firmware
9205 Lte Modem FirmwareAqt1000 Firmware+305 more
Oct 6, 2025
Apr 7, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
There may be information disclosure during memory re-allocation in TZ Secure OS.
1Qualcomm
189Aqt1000 Firmware
Ar8035 FirmwareFastconnect 6200 Firmware+186 more
Oct 3, 2025
Apr 7, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.
1Qualcomm
323205 Mobile Platform Firmware
315 5g Iot Modem Firmware9205 Lte Modem Firmware+320 more
Dec 12, 2024
Dec 2, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
1Qualcomm
208315 5g Iot Modem Firmware
Aqt1000 FirmwareAr8035 Firmware+205 more
Dec 12, 2024
Dec 2, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
1Qualcomm
117Ar8035 Firmware
Fastconnect 6200 FirmwareFastconnect 6700 Firmware+114 more
Nov 7, 2024
Nov 4, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption during GNSS HAL process initialization.
1Qualcomm
263205 Mobile Platform Firmware
215 Mobile Platform Firmware315 5g Iot Modem Firmware+260 more
Nov 7, 2024
Nov 4, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while processing voice packet with arbitrary data received from ADSP.
1Qualcomm
146Ar8035 Firmware
Csra6620 FirmwareCsra6640 Firmware+143 more
Nov 7, 2024
Nov 4, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
1Qualcomm
229315 5g Iot Modem Firmware
Aqt1000 FirmwareAr8035 Firmware+226 more
Nov 8, 2024
Nov 4, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
1Qualcomm
91205 Mobile Platform Firmware
Apq8017 FirmwareApq8037 Firmware+88 more
Nov 7, 2024
Nov 4, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
1Qualcomm
118Ar8035 Firmware
Fastconnect 6200 FirmwareFastconnect 6700 Firmware+115 more
Aug 11, 2025
Oct 7, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers.
1Qualcomm
243215 Mobile Firmware
315 5g Iot FirmwareAqt1000 Firmware+240 more
Aug 11, 2025
Sep 2, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption when two threads try to map and unmap a single node simultaneously.