threat
engine
.sh
Back
·
··:··
Home
/
Product
/
qualcomm qcn9002 firmware
Product
qualcomm qcn9002 firmware
74 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2025-47403
all versions
Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
6.5
MEDIUM
CVE-2025-47331
all versions
Information disclosure while processing a firmware event.
6.1
MEDIUM
CVE-2025-27074
all versions
Memory corruption while processing a GP command response.
8.8
HIGH
CVE-2025-27060
all versions
Memory corruption while performing SCM call with malformed inputs.
8.8
HIGH
CVE-2025-27059
all versions
Memory corruption while performing SCM call.
8.8
HIGH
CVE-2025-27040
all versions
Information disclosure may occur while processing the hypervisor log.
6.5
MEDIUM
CVE-2025-47318
all versions
Transient DOS while parsing the EPTM test control message to get the test pattern.
7.5
HIGH
CVE-2025-27073
all versions
Transient DOS while creating NDP instance.
7.5
HIGH
CVE-2025-27066
all versions
Transient DOS while processing an ANQP message.
7.5
HIGH
CVE-2025-27061
all versions
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmwar
7.8
HIGH
CVE-2025-27042
all versions
Memory corruption while processing video packets received from video firmware.
7.8
HIGH
CVE-2025-21446
all versions
Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.
7.5
HIGH
CVE-2025-21448
all versions
Transient DOS may occur while parsing SSID in action frames.
7.5
HIGH
CVE-2024-38408
all versions
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
8.2
HIGH
CVE-2024-23368
all versions
Memory corruption when allocating and accessing an entry in an SMEM partition.
7.8
HIGH
CVE-2024-21473
all versions
Memory corruption while redirecting log file to any file location with any file name.
9.8
CRITICAL
CVE-2023-33105
all versions
Transient DOS in WLAN Host and Firmware when large number of open authentication frames are sent with an invalid transaction seque
7.5
HIGH
CVE-2023-28578
all versions
Memory corruption in Core Services while executing the command for removing a single event listener.
9.3
CRITICAL
CVE-2023-43536
all versions
Transient DOS while parse fils IE with length equal to 1.
7.5
HIGH
CVE-2023-43523
all versions
Transient DOS while processing 11AZ RTT management action frame received through OTA.
7.5
HIGH
CVE-2023-43522
all versions
Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.
7.5
HIGH
CVE-2023-43513
all versions
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitr
7.8
HIGH
CVE-2023-43511
all versions
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains
IPPROTO_NONE
as the n
7.5
HIGH
CVE-2023-33109
all versions
Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.
7.5
HIGH
CVE-2023-33062
all versions
Transient DOS in WLAN Firmware while parsing a BTM request.
7.5
HIGH
CVE-2023-33098
all versions
Transient DOS while parsing WPA IES, when it is passed with length more than expected size.
7.5
HIGH
CVE-2023-33097
all versions
Transient DOS in WLAN Firmware while processing a FTMR frame.
7.5
HIGH
CVE-2023-33089
all versions
Transient DOS when processing a NULL buffer while parsing WLAN vdev.
7.5
HIGH
CVE-2023-33088
all versions
Memory corruption when processing cmd parameters while parsing vdev.
8.4
HIGH
CVE-2023-33080
all versions
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
7.5
HIGH
CVE-2023-33047
all versions
Transient DOS in WLAN Firmware while parsing no-inherit IES.
7.5
HIGH
CVE-2023-33028
all versions
Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.
9.8
CRITICAL
CVE-2023-33027
all versions
Transient DOS in WLAN Firmware while parsing rsn ies.
7.5
HIGH
CVE-2023-33026
all versions
Transient DOS in WLAN Firmware while parsing a NAN management frame.
7.5
HIGH
CVE-2023-28573
all versions
Memory corruption in WLAN HAL while parsing WMI command parameters.
7.8
HIGH
CVE-2023-28567
all versions
Memory corruption in WLAN HAL while handling command through WMI interfaces.
7.8
HIGH
CVE-2023-28557
all versions
Memory corruption in WLAN HAL while processing command parameters from untrusted WMI payload.
7.8
HIGH
CVE-2023-28549
all versions
Memory corruption in WLAN HAL while parsing Rx buffer in processing TLV payload.
7.8
HIGH
CVE-2023-28548
all versions
Memory corruption in WLAN HAL while processing Tx/Rx commands from QDART.
7.8
HIGH
CVE-2022-33275
all versions
Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range.
8.4
HIGH
CVE-2023-28541
all versions
Memory Corruption in Data Modem while processing DMA buffer release event about CFR data.
7.8
HIGH
CVE-2023-24854
all versions
Memory Corruption in WLAN HOST while parsing QMI WLAN Firmware response message.
7.8
HIGH
CVE-2023-24851
all versions
Memory Corruption in WLAN HOST while parsing QMI response message from firmware.
7.8
HIGH
CVE-2023-22386
all versions
Memory Corruption in WLAN HOST while processing WLAN FW request to allocate memory.
7.8
HIGH
CVE-2023-21661
all versions
Transient DOS while parsing WLAN beacon or probe-response frame.
7.5
HIGH
CVE-2023-21659
all versions
Transient DOS in WLAN Firmware while processing frames with missing header fields.
7.5
HIGH
CVE-2023-21658
all versions
Transient DOS in WLAN Firmware while processing the received beacon or probe response frame.
7.5
HIGH
CVE-2022-22076
all versions
information disclosure due to cryptographic issue in Core during RPMB read request.
7.1
HIGH
CVE-2022-40532
all versions
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.
8.4
HIGH
CVE-2022-40531
all versions
Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message.
8.4
HIGH
CVE-2022-40527
all versions
Transient DOS due to reachable assertion in WLAN while processing PEER ID populated by TQM.
7.5
HIGH
CVE-2022-40512
all versions
Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon.
7.5
HIGH
CVE-2022-40502
all versions
Transient DOS due to improper input validation in WLAN Host.
7.5
HIGH
CVE-2022-34146
all versions
Transient DOS due to improper input validation in WLAN Host while parsing frame during defragmentation.
7.5
HIGH
CVE-2022-34145
all versions
Transient DOS due to buffer over-read in WLAN Host while parsing frame information.
7.5
HIGH
CVE-2022-33306
all versions
Transient DOS due to buffer over-read in WLAN while processing an incoming management frame with incorrectly filled IEs.
7.5
HIGH
CVE-2022-33277
all versions
Memory corruption in modem due to buffer copy without checking size of input while receiving WMI command.
8.4
HIGH
CVE-2022-33271
all versions
Information disclosure due to buffer over-read in WLAN while parsing NMF frame.
8.2
HIGH
CVE-2022-33286
all versions
Transient DOS due to buffer over-read in WLAN while processing 802.11 management frames.
7.5
HIGH
CVE-2022-33285
all versions
Transient DOS due to buffer over-read in WLAN while parsing WLAN CSA action frames.
7.5
HIGH
CVE-2022-33284
all versions
Information disclosure due to buffer over-read in WLAN while parsing BTM action frame.
8.2
HIGH
CVE-2022-33283
all versions
Information disclosure due to buffer over-read in WLAN while WLAN frame parsing due to missing frame length check.
8.2
HIGH
CVE-2022-33276
all versions
Memory corruption due to buffer copy without checking size of input in modem while receiving WMI_REQUEST_STATS_CMDID command.
8.4
HIGH
CVE-2022-33253
all versions
Transient DOS due to buffer over-read in WLAN while parsing corrupted NAN frames.
7.5
HIGH
CVE-2022-33252
all versions
Information disclosure due to buffer over-read in WLAN while handling IBSS beacons frame.
8.2
HIGH
CVE-2022-33238
all versions
Transient DOS due to loop with unreachable exit condition in WLAN while processing an incoming FTM frames. in Snapdragon Auto, Sna
7.5
HIGH
CVE-2022-33235
all versions
Information disclosure due to buffer over-read in WLAN firmware while parsing security context info attributes. in Snapdragon Auto
8.2
HIGH
CVE-2022-33239
all versions
Transient DOS due to loop with unreachable exit condition in WLAN firmware while parsing IPV6 extension header. in Snapdragon Auto
7.5
HIGH
CVE-2022-33237
all versions
Transient DOS due to buffer over-read in WLAN firmware while processing PPE threshold. in Snapdragon Auto, Snapdragon Compute, Sna
7.5
HIGH
CVE-2022-33236
all versions
Transient DOS due to buffer over-read in WLAN firmware while parsing cipher suite info attributes. in Snapdragon Compute, Snapdrag
7.5
HIGH
CVE-2022-25667
all versions
Information disclosure in kernel due to improper handling of ICMP requests in Snapdragon Wired Infrastructure and Networking
7.5
HIGH
CVE-2022-25749
all versions
Transient Denial-of-Service in WLAN due to buffer over-read while parsing MDNS frames. in Snapdragon Auto, Snapdragon Compute, Sna
7.5
HIGH
CVE-2022-25748
all versions
Memory corruption in WLAN due to integer overflow to buffer overflow while parsing GTK frames. in Snapdragon Auto, Snapdragon Comp
9.8
CRITICAL
CVE-2022-25736
all versions
Denial of service in WLAN due to out-of-bound read happens while processing VHT action frame in Snapdragon Auto, Snapdragon Comput
7.5
HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin