📦 Snapdragon Auto 5g Modem Rf Firmware

by Qualcomm

🔍 What is Snapdragon Auto 5g Modem Rf Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-27034

CRITICAL CVSS 9.8 Sep 24, 2025

This vulnerability allows memory corruption during PLMN selection from the SOR failed list in Qualcomm chipsets, potentially enabling remote code execution. It affects devices using vulnerable Qualcom...

CVE-2025-21450

CRITICAL CVSS 9.1 Jul 8, 2025

This vulnerability allows attackers to intercept or manipulate data during downloads due to insecure connection methods. It affects systems using Qualcomm components with vulnerable firmware versions....

CVE-2023-43551

CRITICAL CVSS 9.1 Jun 3, 2024

This vulnerability allows a rogue LTE base station to bypass authentication during network attachment, enabling man-in-the-middle attacks. It affects mobile devices with Qualcomm chipsets that handle ...

CVE-2023-28578

CRITICAL CVSS 9.3 Mar 4, 2024

CVE-2023-28578 is a memory corruption vulnerability in Qualcomm Core Services that occurs when removing a single event listener. This allows attackers to potentially execute arbitrary code or cause de...

CVE-2023-33072

CRITICAL CVSS 9.3 Feb 6, 2024

This CVE describes a memory corruption vulnerability in Qualcomm Core components that could allow attackers to execute arbitrary code or cause denial of service. It affects devices using vulnerable Qu...

CVE-2023-33032

CRITICAL CVSS 9.3 Jan 2, 2024

This vulnerability allows memory corruption in the TrustZone Secure OS when requesting memory allocation from the Trusted Application region. It affects Qualcomm chipsets with TrustZone technology, po...

CVE-2023-33028

CRITICAL CVSS 9.8 Oct 3, 2023

This vulnerability allows memory corruption in Qualcomm WLAN firmware during PMK cache operations, potentially enabling remote code execution. It affects devices with vulnerable Qualcomm WLAN chipsets...

CVE-2023-28540

CRITICAL CVSS 9.1 Oct 3, 2023

This vulnerability in Qualcomm Data Modem chips allows attackers to bypass TLS authentication during handshake, potentially enabling man-in-the-middle attacks. It affects devices using vulnerable Qual...

CVE-2022-33288

CRITICAL CVSS 9.3 Apr 13, 2023

CVE-2022-33288 is a critical buffer overflow vulnerability in Qualcomm's Core component that allows memory corruption when sending SCM commands to retrieve write protection information. Attackers can ...

CVE-2022-33231

CRITICAL CVSS 9.3 Apr 13, 2023

CVE-2022-33231 is a double-free memory corruption vulnerability in Qualcomm chipsets that occurs during encryption key initialization. Successful exploitation could allow attackers to execute arbitrar...

CVE-2026-21385

HIGH CVSS 7.8 Mar 2, 2026

This CVE describes a memory corruption vulnerability in alignment-based memory allocation functions. Attackers can exploit this to execute arbitrary code or cause denial of service. The vulnerability ...

CVE-2025-47376

HIGH CVSS 7.8 Mar 2, 2026

This vulnerability allows memory corruption when multiple processes concurrently access a shared buffer during IOCTL calls in Qualcomm components. Attackers could potentially execute arbitrary code or...

CVE-2025-47320

HIGH CVSS 7.8 Dec 18, 2025

This vulnerability allows memory corruption during MFC channel configuration while playing music, potentially enabling arbitrary code execution. It affects devices with Qualcomm chipsets that use the ...

CVE-2025-27053

HIGH CVSS 7.8 Oct 9, 2025

This vulnerability allows memory corruption in Qualcomm's PlayReady APP implementation when processing TA commands, potentially enabling arbitrary code execution. It affects devices with Qualcomm chip...

CVE-2025-47318

HIGH CVSS 7.5 Sep 24, 2025

This vulnerability allows attackers to cause a denial of service (DoS) condition by sending specially crafted EPTM test control messages. It affects systems using Qualcomm components that process thes...

CVE-2025-21482

HIGH CVSS 7.1 Sep 24, 2025

This CVE describes a cryptographic vulnerability in RSA PKCS padding decoding that could allow attackers to decrypt sensitive data or forge digital signatures. It affects Qualcomm products implementin...

CVE-2025-21477

HIGH CVSS 7.5 Aug 6, 2025

This vulnerability allows attackers to cause a Denial of Service (DoS) condition in affected Qualcomm systems by sending specially crafted CCCH data with invalid length. The vulnerability affects mobi...

CVE-2025-21452

HIGH CVSS 7.5 Aug 6, 2025

This vulnerability allows attackers to cause a denial-of-service (DoS) condition on LTE networks by sending specially crafted random-access response (RAR) messages with invalid PDU lengths. It affects...

CVE-2025-27043

HIGH CVSS 7.8 Jul 8, 2025

This vulnerability allows memory corruption in Qualcomm video firmware when processing manipulated payloads. Attackers could potentially execute arbitrary code or cause denial of service. Affects devi...

CVE-2025-21446

HIGH CVSS 7.5 Jul 8, 2025

This vulnerability allows a denial-of-service (DoS) condition in Qualcomm wireless LAN (WLAN) chipsets when processing vendor-specific information elements in BTM (BSS Transition Management) request f...

CVE-2025-21468

HIGH CVSS 7.8 May 6, 2025

This vulnerability allows memory corruption in Qualcomm firmware drivers when processing responses. Attackers could potentially execute arbitrary code or cause denial of service on affected devices. T...

CVE-2025-21429

HIGH CVSS 7.5 Apr 7, 2025

This vulnerability allows memory corruption during Wi-Fi connection establishment between a station (STA) and access point (AP) when initiating an ADD TS (Traffic Stream) request. Attackers could pote...

CVE-2024-43066

HIGH CVSS 7.8 Apr 7, 2025

This CVE describes a use-after-free vulnerability (CWE-416) in Qualcomm components that occurs during file descriptor handling in listener registration/deregistration processes. Successful exploitatio...

CVE-2025-21424

HIGH CVSS 7.8 Mar 3, 2025

This CVE describes a use-after-free vulnerability (CWE-416) in Qualcomm NPU driver APIs that can be triggered through concurrent calls, leading to memory corruption. It affects devices with Qualcomm c...

CVE-2024-53027

HIGH CVSS 7.5 Mar 3, 2025

This vulnerability in Qualcomm components allows a denial-of-service attack when processing country information elements. It affects devices using Qualcomm chipsets, potentially causing temporary serv...

CVE-2024-33044

HIGH CVSS 8.4 Dec 2, 2024

This vulnerability allows memory corruption when configuring SMR/S2CR registers in Bypass mode on Qualcomm chipsets. Attackers could potentially execute arbitrary code or cause denial of service. Affe...

CVE-2024-33056

HIGH CVSS 8.4 Dec 2, 2024

CVE-2024-33056 is a memory corruption vulnerability in Qualcomm's Shared Memory (SMEM) subsystem that allows attackers to potentially execute arbitrary code or cause denial of service. This affects de...

CVE-2024-38423

HIGH CVSS 7.8 Nov 4, 2024

This vulnerability allows memory corruption during GPU page table switching in Qualcomm GPU drivers. Attackers could potentially execute arbitrary code or cause denial of service. Affects devices usin...

CVE-2024-38415

HIGH CVSS 7.8 Nov 4, 2024

This CVE describes a use-after-free vulnerability (CWE-416) in Qualcomm firmware that occurs when handling session errors. An attacker could exploit this memory corruption to execute arbitrary code or...

CVE-2024-43047

HIGH CVSS 7.8 Oct 7, 2024

This CVE describes a use-after-free vulnerability (CWE-416) in Qualcomm's memory management subsystem that allows attackers to corrupt memory while maintaining memory maps of HLOS (High-Level Operatin...

CVE-2024-33049

HIGH CVSS 7.5 Oct 7, 2024

This vulnerability allows an attacker to cause a denial-of-service (DoS) condition by sending specially crafted beacon frames with specific Extension element parameters. It affects systems using Qualc...

CVE-2024-38402

HIGH CVSS 7.8 Sep 2, 2024

This vulnerability allows attackers to cause memory corruption through a specific IOCTL call for group information retrieval. Successful exploitation could lead to arbitrary code execution or system c...

CVE-2024-33060

HIGH CVSS 8.4 Sep 2, 2024

This vulnerability allows memory corruption when two threads simultaneously map and unmap a single node in Qualcomm components. Successful exploitation could lead to arbitrary code execution or system...

CVE-2024-33045

HIGH CVSS 8.4 Sep 2, 2024

This vulnerability allows memory corruption when the BTFM client sends new messages over Slimbus to the ADSP in Qualcomm chipsets. Attackers could potentially execute arbitrary code or cause denial of...

CVE-2024-33028

HIGH CVSS 8.4 Aug 5, 2024

This CVE describes a use-after-free vulnerability in Qualcomm graphics drivers where a fence object may still be accessed after being released during timeline destruction. This memory corruption could...

CVE-2024-33022

HIGH CVSS 8.4 Aug 5, 2024

This vulnerability allows memory corruption in the HGSL driver when allocating memory, potentially leading to arbitrary code execution or system crashes. It affects devices using Qualcomm chipsets wit...

CVE-2024-33012

HIGH CVSS 7.5 Aug 5, 2024

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in Wi-Fi systems by sending specially crafted beacon frames with malformed MBSSID information elements. It affects devi...

CVE-2024-33014

HIGH CVSS 7.5 Aug 5, 2024

This vulnerability allows an attacker to cause a Denial of Service (DoS) by sending specially crafted beacon or probe response frames containing malformed ESP IE (Extended Service Period Information E...

CVE-2024-33010

HIGH CVSS 7.5 Aug 5, 2024

This vulnerability allows attackers to cause a denial-of-service (DoS) condition by sending specially crafted MBSSID Information Element fragments in Wi-Fi beacon frames. It affects systems using Qual...

CVE-2024-23352

HIGH CVSS 7.5 Aug 5, 2024

This vulnerability allows attackers to cause a denial of service (DoS) in NAS (Network Access Stratum) implementations by sending specially crafted ODAC criteria in registration accept OTA messages. I...

CVE-2024-23373

HIGH CVSS 8.4 Jul 1, 2024

This vulnerability allows memory corruption when IOMMU unmap operations fail, leading to improper release of DMA and anonymous buffers. It affects systems using Qualcomm chipsets with vulnerable IOMMU...

CVE-2024-23368

HIGH CVSS 7.8 Jul 1, 2024

This CVE describes a memory corruption vulnerability in Qualcomm's Shared Memory (SMEM) subsystem that could allow attackers to execute arbitrary code or cause denial of service. The vulnerability aff...

CVE-2024-21462

HIGH CVSS 7.1 Jul 1, 2024

This vulnerability allows a denial-of-service attack when loading Trusted Application (TA) ELF files on Qualcomm chipsets. It affects devices using Qualcomm processors with vulnerable firmware. Attack...

CVE-2023-43529

HIGH CVSS 7.5 May 6, 2024

This vulnerability allows attackers to cause a denial-of-service condition in IKEv2 implementations by sending malformed fragment packets. It affects systems using Qualcomm's IKEv2 implementation, pot...

CVE-2024-21468

HIGH CVSS 8.4 Apr 1, 2024

CVE-2024-21468 is a use-after-free vulnerability in Qualcomm GPU drivers where failed memory unmapping operations can lead to memory corruption. This allows attackers to potentially execute arbitrary ...

CVE-2024-21452

HIGH CVSS 7.3 Apr 1, 2024

This vulnerability allows attackers to cause a denial-of-service (DoS) condition by sending specially crafted ASN.1 OER messages containing unknown extensions to vulnerable systems. It affects Qualcom...

CVE-2023-33099

HIGH CVSS 7.5 Apr 1, 2024

This vulnerability allows a denial-of-service (DoS) attack on 5G NR (New Radio) devices by sending specially crafted SMS messages with non-standard container sizes. It affects mobile devices using Qua...

CVE-2023-33101

HIGH CVSS 7.5 Apr 1, 2024

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in Qualcomm devices by sending specially crafted DL NAS TRANSPORT messages with zero payload length. It affects mobile ...

CVE-2023-28547

HIGH CVSS 8.4 Apr 1, 2024

This CVE describes a memory corruption vulnerability in the SPS Application's sorter Trusted Application (TA) when requesting public keys. Successful exploitation could allow attackers to execute arbi...

CVE-2023-43546

HIGH CVSS 8.4 Mar 4, 2024

This vulnerability allows memory corruption when invoking the HGSL IOCTL context create function in Qualcomm GPU drivers. Attackers could potentially execute arbitrary code with kernel privileges. Aff...

CVE-2025-47384

MEDIUM CVSS 6.5 Mar 2, 2026

This vulnerability allows a denial-of-service (DoS) condition in Qualcomm MAC (Media Access Control) components when an attacker configures a MAC configuration ID beyond the supported maximum value. T...

CVE-2025-47371

MEDIUM CVSS 6.5 Mar 2, 2026

This vulnerability allows a denial-of-service (DoS) attack against LTE user equipment (UE) when it receives an RLC packet with an invalid transport block (TB). Mobile devices using affected Qualcomm c...

CVE-2025-47369

MEDIUM CVSS 5.5 Jan 7, 2026

This vulnerability allows information disclosure when a weak hashed value is returned to userland code in response to an IOCTL call to obtain a session ID. Attackers can potentially extract sensitive ...

CVE-2025-47330

MEDIUM CVSS 5.5 Jan 7, 2026

This vulnerability allows an attacker to cause a temporary denial of service (DoS) by sending specially crafted video packets to vulnerable systems. It affects devices using Qualcomm video firmware co...

CVE-2025-47331

MEDIUM CVSS 6.1 Jan 7, 2026

This CVE describes an information disclosure vulnerability in Qualcomm firmware that leaks sensitive data when processing firmware events. It affects devices using vulnerable Qualcomm chipsets, potent...

CVE-2025-47333

MEDIUM CVSS 6.6 Jan 7, 2026

This vulnerability allows memory corruption in Qualcomm's cryptographic driver when handling buffer mapping operations. Attackers could potentially execute arbitrary code or cause denial of service. A...

CVE-2025-47370

MEDIUM CVSS 6.5 Nov 4, 2025

This vulnerability allows a remote attacker to cause a denial of service (DoS) by sending invalid Bluetooth Low Energy (LE) connection requests during a connectable scan. It affects devices with Qualc...

CVE-2025-27030

MEDIUM CVSS 6.1 Sep 24, 2025

This CVE-2025-27030 vulnerability allows unauthorized information disclosure when calibration data is invoked from user space to update firmware size. It affects Qualcomm devices and systems using vul...

CVE-2025-21464

MEDIUM CVSS 6.5 Aug 6, 2025

This vulnerability allows attackers to read sensitive information from image processing operations by manipulating offset and size parameters. It affects systems using Qualcomm components with vulnera...

CVE-2025-21465

MEDIUM CVSS 6.5 Aug 6, 2025

This vulnerability allows attackers to read sensitive information from memory when processing specially crafted MBN files. It affects systems using Qualcomm chipsets that process MBN files, potentiall...