Sar2130p Firmware
by Qualcomm
CVEs (28)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-47402 | Med | 0.42 | 6.5 | 0.00 | Feb 2, 2026 | Transient DOS when processing a received frame with an excessively large authentication information element. | ||
| CVE-2025-59609 | Med | 0.36 | 5.5 | 0.00 | Jun 1, 2026 | Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length. | ||
| CVE-2026-25268 | Hig | 0.00 | 8.8 | 0.00 | Jul 6, 2026 | Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations. | ||
| CVE-2026-21384 | Med | 0.00 | 5.3 | 0.00 | Jul 6, 2026 | Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits. | ||
| CVE-2026-21383 | Hig | 0.00 | 7.1 | 0.00 | Jul 6, 2026 | Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security. | ||
| CVE-2026-21370 | Med | 0.00 | 5.3 | 0.00 | Jul 6, 2026 | Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values. | ||
| CVE-2026-21369 | Med | 0.00 | 5.3 | 0.00 | Jul 6, 2026 | Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification. | ||
| CVE-2026-21368 | Med | 0.00 | 5.3 | 0.00 | Jul 6, 2026 | Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks. |
- risk 0.42cvss 6.5epss 0.00
Transient DOS when processing a received frame with an excessively large authentication information element.
- risk 0.36cvss 5.5epss 0.00
Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.
- risk 0.00cvss 8.8epss 0.00
Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.
- risk 0.00cvss 5.3epss 0.00
Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits.
- risk 0.00cvss 7.1epss 0.00
Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security.
- risk 0.00cvss 5.3epss 0.00
Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values.
- risk 0.00cvss 5.3epss 0.00
Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification.
- risk 0.00cvss 5.3epss 0.00
Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks.
Page 2 of 2