Sdx61 Firmware
by Qualcomm
CVEs (71)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-21448 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Transient DOS may occur while parsing SSID in action frames. | ||
| CVE-2025-21430 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session. | ||
| CVE-2025-21429 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request. | ||
| CVE-2024-53027 | Hig | 0.49 | 7.5 | 0.00 | Mar 3, 2025 | Transient DOS may occur while processing the country IE. | ||
| CVE-2024-23385 | Hig | 0.49 | 7.5 | 0.00 | Nov 4, 2024 | Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE. | ||
| CVE-2024-33051 | Hig | 0.49 | 7.5 | 0.00 | Sep 2, 2024 | Transient DOS while processing TIM IE from beacon frame as there is no check for IE length. | ||
| CVE-2024-33050 | Hig | 0.49 | 7.5 | 0.00 | Sep 2, 2024 | Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper. | ||
| CVE-2024-23364 | Hig | 0.49 | 7.5 | 0.00 | Sep 2, 2024 | Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air (OTA). | ||
| CVE-2026-24091 | Hig | 0.47 | 7.2 | 0.00 | Jun 1, 2026 | Memory corruption while processing fastboot commands with improperly formatted input. | ||
| CVE-2026-24085 | Hig | 0.47 | 7.2 | 0.00 | Jun 1, 2026 | Memory Corruption when processing display command line information due to improper initialization of a variable. | ||
| CVE-2025-47383 | Hig | 0.47 | 7.2 | 0.00 | Mar 2, 2026 | Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE. | ||
| CVE-2025-21482 | Hig | 0.46 | 7.1 | 0.00 | Sep 24, 2025 | Cryptographic issue while performing RSA PKCS padding decoding. | ||
| CVE-2025-21422 | Hig | 0.46 | 7.1 | 0.00 | Jul 8, 2025 | Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses. | ||
| CVE-2024-23362 | Hig | 0.46 | 7.1 | 0.00 | Sep 2, 2024 | Cryptographic issue while parsing RSA keys in COBR format. | ||
| CVE-2024-33016 | Med | 0.44 | 6.8 | 0.00 | Sep 2, 2024 | memory corruption when an invalid firehose patch command is invoked. | ||
| CVE-2025-47333 | Med | 0.43 | 6.6 | 0.00 | Jan 7, 2026 | Memory corruption while handling buffer mapping operations in the cryptographic driver. | ||
| CVE-2026-24078 | Med | 0.42 | 6.5 | 0.00 | Aug 4, 2026 | Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling. | ||
| CVE-2025-47403 | Med | 0.42 | 6.5 | 0.00 | May 4, 2026 | Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming. | ||
| CVE-2025-47401 | Med | 0.42 | 6.5 | 0.00 | May 4, 2026 | Transient DOS when processing target power rate tables during channel configuration. | ||
| CVE-2025-47371 | Med | 0.42 | 6.5 | 0.00 | Mar 2, 2026 | Transient DOS when an LTE RLC packet with invalid TB is received by UE. |
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur while parsing SSID in action frames.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
- risk 0.49cvss 7.5epss 0.00
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur while processing the country IE.
- risk 0.49cvss 7.5epss 0.00
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper.
- risk 0.49cvss 7.5epss 0.00
Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air (OTA).
- risk 0.47cvss 7.2epss 0.00
Memory corruption while processing fastboot commands with improperly formatted input.
- risk 0.47cvss 7.2epss 0.00
Memory Corruption when processing display command line information due to improper initialization of a variable.
- risk 0.47cvss 7.2epss 0.00
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue while performing RSA PKCS padding decoding.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue while parsing RSA keys in COBR format.
- risk 0.44cvss 6.8epss 0.00
memory corruption when an invalid firehose patch command is invoked.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while handling buffer mapping operations in the cryptographic driver.
- risk 0.42cvss 6.5epss 0.00
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
- risk 0.42cvss 6.5epss 0.00
Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
- risk 0.42cvss 6.5epss 0.00
Transient DOS when processing target power rate tables during channel configuration.
- risk 0.42cvss 6.5epss 0.00
Transient DOS when an LTE RLC packet with invalid TB is received by UE.
Page 3 of 4