← Back

Onsemi

onsemi

8 CVEs • 36 products

Products (36)

Click to collapse
Toggle
Qcs Ax3 S5
qcs-ax3-s5
Qcs Ax2 A12
qcs-ax2-a12
Qcs Ax2 T12
qcs-ax2-t12
Qcs Ax2 T8
qcs-ax2-t8
Qd840
qd840
Qhs710
qhs710
Qsr10ga
qsr10ga
Qsr10gu
qsr10gu
Qv840
qv840
Qv840c
qv840c
Qv860
qv860
Qv940
qv940
Qv942c
qv942c
Qv952c
qv952c
Qcs Ax2 S5
qcs-ax2-s5
Qcs Ax3 A12
qcs-ax3-a12
Qcs Ax3 T12
qcs-ax3-t12
Qcs Ax3 T8
qcs-ax3-t8

CVEs (8)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Onsemi
18Qcs Ax2 A12 Firmware
Qcs Ax2 S5 FirmwareQcs Ax2 T12 Firmware+15 more
Jun 17, 2026
Jun 8, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Quantenna Wi-Fi chips ship with an unauthenticated telnet interface by default. This is an instance of CWE-306, "Missing Authentication for Critical Function," and is estimated as a CVSS 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/...Show more
The Quantenna Wi-Fi chips ship with an unauthenticated telnet interface by default. This is an instance of CWE-306, "Missing Authentication for Critical Function," and is estimated as a CVSS 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This issue affects Quantenna Wi-Fi chipset through version 8.0.0.28 of the latest SDK, and appears to be unpatched at the time of this CVE record's first publishing, though the vendor has released a best practices guide for implementors of this chipset.Show less
1Onsemi
18Qcs Ax2 A12 Firmware
Qcs Ax2 S5 FirmwareQcs Ax2 T12 Firmware+15 more
Jun 17, 2026
Jun 8, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
The Quantenna Wi-Fi chipset ships with a local control script, set_tx_pow, that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument I...Show more
The Quantenna Wi-Fi chipset ships with a local control script, set_tx_pow, that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.7 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This issue affects Quantenna Wi-Fi chipset through version 8.0.0.28 of the latest SDK, and appears to be unpatched at the time of this CVE record's first publishing, though the vendor has released a best practices guide for implementors of this chipset.Show less
1Onsemi
18Qcs Ax2 A12 Firmware
Qcs Ax2 S5 FirmwareQcs Ax2 T12 Firmware+15 more
Jun 17, 2026
Jun 8, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
The Quantenna Wi-Fi chipset ships with a local control script, transmit_file, that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argumen...Show more
The Quantenna Wi-Fi chipset ships with a local control script, transmit_file, that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.7 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This issue affects Quantenna Wi-Fi chipset through version 8.0.0.28 of the latest SDK, and appears to be unpatched at the time of this CVE record's first publishing, though the vendor has released a best practices guide for implementors of this chipset.Show less
1Onsemi
18Qcs Ax2 A12 Firmware
Qcs Ax2 S5 FirmwareQcs Ax2 T12 Firmware+15 more
Jun 17, 2026
Jun 8, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the sync_time argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument D...Show more
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the sync_time argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.7 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This issue affects Quantenna Wi-Fi chipset through version 8.0.0.28 of the latest SDK, and appears to be unpatched at the time of this CVE record's first publishing, though the vendor has released a best practices guide for implementors of this chipset.Show less
1Onsemi
18Qcs Ax2 A12 Firmware
Qcs Ax2 S5 FirmwareQcs Ax2 T12 Firmware+15 more
Jun 17, 2026
Jun 8, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the get_syslog_from_qtn argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of...Show more
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the get_syslog_from_qtn argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.7 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This issue affects Quantenna Wi-Fi chipset through version 8.0.0.28 of the latest SDK, and appears to be unpatched at the time of this CVE record's first publishing, though the vendor has released a best practices guide for implementors of this chipset.Show less
1Onsemi
18Qcs Ax2 A12 Firmware
Qcs Ax2 S5 FirmwareQcs Ax2 T12 Firmware+15 more
Jun 17, 2026
Jun 8, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the get_file_from_qtn argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Ar...Show more
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the get_file_from_qtn argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.7 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This issue affects Quantenna Wi-Fi chipset through version 8.0.0.28 of the latest SDK, and appears to be unpatched at the time of this CVE record's first publishing, though the vendor has released a best practices guide for implementors of this chipset.Show less
1Onsemi
18Qcs Ax2 A12 Firmware
Qcs Ax2 S5 FirmwareQcs Ax2 T12 Firmware+15 more
Jun 17, 2026
Jun 8, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the put_file_to_qtn argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argu...Show more
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the put_file_to_qtn argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.7 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This issue affects Quantenna Wi-Fi chipset through version 8.0.0.28 of the latest SDK, and appears to be unpatched at the time of this CVE record's first publishing, though the vendor has released a best practices guide for implementors of this chipset.Show less
1Onsemi
18Qcs Ax2 A12 Firmware
Qcs Ax2 S5 FirmwareQcs Ax2 T12 Firmware+15 more
Jun 17, 2026
Jun 8, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the run_cmd argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Del...Show more
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the run_cmd argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.7 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This issue affects Quantenna Wi-Fi chipset through version 8.0.0.28 of the latest SDK, and appears to be unpatched at the time of this CVE record's first publishing, though the vendor has released a best practices guide for implementors of this chipset.Show less