Vulnerabilities (CVE)

Filtered by vendor Qualcomm Subscribe
Filtered by product Qca6688aq
Total 105 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-53027 1 Qualcomm 424 205, 205 Firmware, Apq8017 and 421 more 2025-08-11 N/A 7.5 HIGH
Transient DOS may occur while processing the country IE.
CVE-2024-53023 1 Qualcomm 206 Ar8035, Ar8035 Firmware, Fastconnect 6900 and 203 more 2025-08-11 N/A 7.8 HIGH
Memory corruption may occur while accessing a variable during extended back to back tests.
CVE-2025-21450 1 Qualcomm 216 Ar8035, Ar8035 Firmware, Fastconnect 6200 and 213 more 2025-08-11 N/A 9.1 CRITICAL
Cryptographic issue occurs due to use of insecure connection method while downloading.
CVE-2025-27057 1 Qualcomm 424 Ar8035, Ar8035 Firmware, Csr8811 and 421 more 2025-08-11 N/A 7.5 HIGH
Transient DOS while handling beacon frames with invalid IE header length.
CVE-2024-33045 1 Qualcomm 360 Ar8035, Ar8035 Firmware, Csra6620 and 357 more 2025-08-11 N/A 7.8 HIGH
Memory corruption when BTFM client sends new messages over Slimbus to ADSP.
CVE-2024-33073 1 Qualcomm 318 Ar8035, Ar8035 Firmware, Csr8811 and 315 more 2025-08-11 N/A 8.2 HIGH
Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
CVE-2024-43051 1 Qualcomm 488 Aqt1000, Aqt1000 Firmware, Ar8031 and 485 more 2025-08-11 N/A 5.5 MEDIUM
Information disclosure while deriving keys for a session for any Widevine use case.
CVE-2024-38397 1 Qualcomm 232 Ar8035, Ar8035 Firmware, Fastconnect 6700 and 229 more 2025-08-11 N/A 7.5 HIGH
Transient DOS while parsing probe response and assoc response frame.
CVE-2025-21433 1 Qualcomm 550 215 Mobile, 215 Mobile Firmware, Apq8017 and 547 more 2025-08-11 N/A 5.5 MEDIUM
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
CVE-2023-43520 1 Qualcomm 140 Ar8035, Ar8035 Firmware, Fastconnect 6900 and 137 more 2025-08-11 N/A 9.8 CRITICAL
Memory corruption when AP includes TID to link mapping IE in the beacons and STA is parsing the beacon TID to link mapping IE.
CVE-2025-27061 1 Qualcomm 688 315 5g Iot, 315 5g Iot Firmware, Aqt1000 and 685 more 2025-08-11 N/A 7.8 HIGH
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
CVE-2023-43533 1 Qualcomm 476 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 473 more 2025-08-11 N/A 7.5 HIGH
Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.
CVE-2025-27043 1 Qualcomm 412 Ar8035, Ar8035 Firmware, Csr8811 and 409 more 2025-08-11 N/A 7.8 HIGH
Memory corruption while processing manipulated payload in video firmware.
CVE-2024-21455 1 Qualcomm 40 Qam8295p, Qam8295p Firmware, Qca6584au and 37 more 2025-08-11 N/A 7.8 HIGH
Memory corruption when a compat IOCTL call is followed by another IOCTL call from userspace to a driver.
CVE-2024-53024 1 Qualcomm 332 Ar8035, Ar8035 Firmware, Csra6620 and 329 more 2025-08-11 N/A 7.8 HIGH
Memory corruption in display driver while detaching a device.
CVE-2025-21446 1 Qualcomm 480 Ar8035, Ar8035 Firmware, Ar9380 and 477 more 2025-08-11 N/A 7.5 HIGH
Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.
CVE-2023-43522 1 Qualcomm 572 Aqt1000, Aqt1000 Firmware, Ar8035 and 569 more 2025-08-11 N/A 7.5 HIGH
Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.
CVE-2024-33057 1 Qualcomm 342 Ar8035, Ar8035 Firmware, Csr8811 and 339 more 2025-08-11 N/A 7.5 HIGH
Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location.
CVE-2024-33049 1 Qualcomm 262 Csr8811, Csr8811 Firmware, Fastconnect 6700 and 259 more 2025-08-11 N/A 7.5 HIGH
Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.
CVE-2023-43513 1 Qualcomm 534 315 5g Iot Modem, 315 5g Iot Modem Firmware, Apq8017 and 531 more 2025-08-11 N/A 7.8 HIGH
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.