📦 Wcn6850 Firmware

by Qualcomm

🔍 What is Wcn6850 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-21651

CRITICAL CVSS 9.3 Aug 8, 2023

CVE-2023-21651 is a memory corruption vulnerability in Qualcomm's Trusted Execution Environment (TEE) due to incorrect type conversion in secure_io_read/write functions. This allows attackers to poten...

CVE-2022-40510

CRITICAL CVSS 9.8 Aug 8, 2023

CVE-2022-40510 is a critical memory corruption vulnerability in Qualcomm audio components that allows attackers to execute arbitrary code or cause denial of service. The vulnerability affects devices ...

CVE-2022-40514

CRITICAL CVSS 9.8 Feb 12, 2023

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service on affected devices by exploiting a buffer overflow in WLAN firmware. It affects Qualcomm chipsets used ...

CVE-2022-33232

CRITICAL CVSS 9.3 Feb 12, 2023

CVE-2022-33232 is a critical buffer overflow vulnerability in Qualcomm memory sharing tests that allows attackers to execute arbitrary code or cause denial of service. This affects devices with Qualco...

CVE-2021-35104

CRITICAL CVSS 9.8 Jun 14, 2022

This vulnerability allows remote attackers to execute arbitrary code on affected Qualcomm Snapdragon devices by exploiting a buffer overflow in the FLAC audio header parser. Attackers can trigger this...

CVE-2021-35081

CRITICAL CVSS 9.8 Jun 14, 2022

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service via buffer overflow in Qualcomm Snapdragon chipsets. It affects devices using vulnerable Snapdragon comp...

CVE-2021-35090

CRITICAL CVSS 9.3 Jun 14, 2022

This vulnerability allows a malicious application to potentially corrupt hypervisor memory through a Time-of-Check Time-of-Use (TOCTOU) race condition when updating address mappings in Qualcomm Snapdr...

CVE-2021-30347

CRITICAL CVSS 9.1 Jun 14, 2022

This vulnerability in Qualcomm Snapdragon chipsets allows improper integrity checks leading to race conditions between PDCP and RRC tasks after receiving valid RRC command packets. Attackers could pot...

CVE-2021-30339

CRITICAL CVSS 9.0 Jun 14, 2022

This vulnerability in Qualcomm Snapdragon chipsets allows improper cryptographic key generation due to insufficient buffer validation when reading PRNG output. Attackers could potentially generate wea...

CVE-2021-30341

CRITICAL CVSS 9.8 Jun 14, 2022

This vulnerability allows improper buffer size validation in DSM packets received by Qualcomm Snapdragon chipsets, leading to memory corruption. Attackers can exploit this to execute arbitrary code or...

CVE-2021-30343

CRITICAL CVSS 9.1 Jun 14, 2022

This vulnerability in Qualcomm Snapdragon chipsets allows improper integrity checks leading to race conditions between PDCP and RRC tasks after receiving valid RRC Command packets. Attackers could pot...

CVE-2021-30317

CRITICAL CVSS 9.3 Feb 11, 2022

This vulnerability allows attackers to bypass image verification in Qualcomm Snapdragon chipsets by exploiting improper validation of ELF metadata in program headers. This affects numerous Snapdragon ...

CVE-2021-30285

CRITICAL CVSS 9.3 Jan 13, 2022

This vulnerability in Qualcomm Snapdragon hypervisors allows improper memory region validation, potentially enabling attackers to map incorrect memory regions. It affects numerous Snapdragon platforms...

CVE-2021-30351

CRITICAL CVSS 9.8 Jan 3, 2022

CVE-2021-30351 is a critical buffer overflow vulnerability in Qualcomm Snapdragon chipsets, allowing attackers to execute arbitrary code or cause denial of service by exploiting improper validation du...

CVE-2021-30275

CRITICAL CVSS 9.3 Jan 3, 2022

This vulnerability is an integer overflow in Qualcomm Snapdragon chipsets that could allow attackers to execute arbitrary code or cause denial of service. It affects multiple Snapdragon product lines ...

CVE-2021-1924

CRITICAL CVSS 9.0 Nov 12, 2021

This vulnerability allows attackers to extract RSA private keys through timing and power side-channel attacks during modular exponentiation in RSA-CRT implementations. It affects Qualcomm Snapdragon c...

CVE-2021-1975

CRITICAL CVSS 9.8 Nov 12, 2021

CVE-2021-1975 is a critical heap overflow vulnerability in Qualcomm Snapdragon chipsets that allows remote code execution via malformed DNS responses. Attackers can exploit this to execute arbitrary c...

CVE-2021-30321

CRITICAL CVSS 9.8 Nov 12, 2021

This vulnerability allows remote code execution via buffer overflow in Qualcomm Snapdragon chipsets when processing MBSSID scan information elements. Attackers can exploit this to execute arbitrary co...

CVE-2021-1976

CRITICAL CVSS 9.8 Sep 17, 2021

This critical vulnerability in Qualcomm Snapdragon chipsets allows remote code execution due to a use-after-free memory corruption flaw in Wi-Fi P2P (peer-to-peer) device address validation. Attackers...

CVE-2021-1946

CRITICAL CVSS 9.8 Sep 9, 2021

A null pointer dereference vulnerability in Qualcomm Snapdragon chipsets allows remote attackers to cause denial of service or potentially execute arbitrary code by sending a specially crafted SDP (Se...

CVE-2023-21646

HIGH CVSS 7.5 Sep 5, 2023

This vulnerability allows attackers to cause a denial-of-service condition in Qualcomm modems by sending specially crafted System Information Block 1 messages. The modem may crash or become unresponsi...

CVE-2023-21662

HIGH CVSS 7.8 Sep 5, 2023

CVE-2023-21662 is a memory corruption vulnerability in Qualcomm's Core Platform that occurs while printing response buffers in logs. This buffer overflow vulnerability could allow attackers to execute...

CVE-2023-21664

HIGH CVSS 7.8 Sep 5, 2023

This vulnerability allows memory corruption in Qualcomm's Core Platform when printing response buffers in logs. Attackers could potentially execute arbitrary code or cause denial of service. Affects d...

CVE-2023-21626

HIGH CVSS 7.1 Aug 8, 2023

This cryptographic vulnerability in Qualcomm's HLOS (High-Level Operating System) allows improper authentication during key velocity checks when multiple keys are involved. It affects devices using Qu...

CVE-2023-22666

HIGH CVSS 8.4 Aug 8, 2023

CVE-2023-22666 is a memory corruption vulnerability in Qualcomm's audio processing component when playing specially crafted AMR-WB+ audio clips. This vulnerability allows attackers to execute arbitrar...

CVE-2022-33272

HIGH CVSS 7.5 Mar 10, 2023

CVE-2022-33272 is a reachable assertion vulnerability in Qualcomm modem firmware that can cause a denial of service (DoS) condition. When exploited, it triggers a modem crash requiring device reboot. ...

CVE-2022-40515

HIGH CVSS 7.3 Mar 10, 2023

This vulnerability allows memory corruption through a double-free error when processing specially crafted 3gp video files with invalid metadata atoms. Attackers could potentially execute arbitrary cod...

CVE-2022-40530

HIGH CVSS 8.4 Mar 10, 2023

This vulnerability allows attackers to execute arbitrary code or cause denial of service on affected Qualcomm WLAN chipsets due to memory corruption during initialization. It affects devices using vul...

CVE-2022-40535

HIGH CVSS 7.5 Mar 10, 2023

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in affected Qualcomm WLAN chipsets by sending specially crafted packets that trigger a buffer over-read. The vulnerabil...

CVE-2022-33243

HIGH CVSS 8.4 Feb 12, 2023

CVE-2022-33243 is a memory corruption vulnerability in Qualcomm's Inter-Processor Communication (IPC) subsystem due to improper access control. This allows attackers to execute arbitrary code or cause...

CVE-2022-33248

HIGH CVSS 7.8 Feb 12, 2023

This vulnerability allows memory corruption in Qualcomm's User Identity Module due to an integer overflow that leads to buffer overflow when processing segments via QMI HTTP. It affects devices using ...

CVE-2022-33277

HIGH CVSS 8.4 Feb 12, 2023

This CVE describes a buffer overflow vulnerability in Qualcomm modem firmware that allows memory corruption when processing WMI commands. Attackers could potentially execute arbitrary code on affected...

CVE-2022-33306

HIGH CVSS 7.5 Feb 12, 2023

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in affected wireless devices by sending specially crafted management frames with malformed information elements (IEs). ...

CVE-2022-22071

HIGH CVSS 8.4 Jun 14, 2022

This is a use-after-free vulnerability in Qualcomm Snapdragon chipsets that allows attackers to execute arbitrary code or cause denial of service. It affects multiple Qualcomm product lines including ...

CVE-2022-22082

HIGH CVSS 8.4 Jun 14, 2022

This vulnerability allows memory corruption via buffer overflow when parsing DSF audio file headers with corrupted channel counts in Qualcomm Snapdragon chipsets. Attackers could potentially execute a...

CVE-2022-22084

HIGH CVSS 8.4 Jun 14, 2022

This vulnerability allows memory corruption when processing QCP audio files due to insufficient length validation in Qualcomm Snapdragon chipsets. Attackers could exploit this to execute arbitrary cod...

CVE-2022-22086

HIGH CVSS 7.3 Jun 14, 2022

This vulnerability allows memory corruption through a double free error when parsing malformed 3gp video files with invalid metadata atoms. It affects devices using Qualcomm Snapdragon chipsets across...

CVE-2022-22090

HIGH CVSS 8.4 Jun 14, 2022

This is a use-after-free vulnerability in Qualcomm Snapdragon audio components that allows memory corruption. Attackers could potentially execute arbitrary code or cause denial of service on affected ...

CVE-2022-22057

HIGH CVSS 8.4 Jun 14, 2022

This is a use-after-free vulnerability in Qualcomm's kgsl graphics driver that occurs due to a race condition when closing fence file descriptors while destroying graphics timelines simultaneously. Su...

CVE-2022-22065

HIGH CVSS 7.5 Jun 14, 2022

This vulnerability is an out-of-bounds read in the WLAN HOST component of Qualcomm Snapdragon chipsets due to improper length checking. It affects multiple Qualcomm Snapdragon product lines including ...

CVE-2021-35112

HIGH CVSS 8.4 Jun 14, 2022

This vulnerability allows a user with standard permissions to access protected graphics memory regions due to improper access control in register configuration on Qualcomm Snapdragon chips. It affects...

CVE-2021-35116

HIGH CVSS 7.7 Jun 14, 2022

This vulnerability allows a malicious Android application (APK) to load a specially crafted model into the Qualcomm CDSP (Compute DSP), potentially compromising the CDSP and accessing data from other ...

CVE-2021-35123

HIGH CVSS 8.8 Jun 14, 2022

This is a buffer overflow vulnerability in Qualcomm's Snapdragon chipsets affecting GATT multi-notification functionality. Attackers can exploit this by sending specially crafted Bluetooth packets to ...

CVE-2021-35129

HIGH CVSS 7.8 Jun 14, 2022

This vulnerability allows memory corruption in Bluetooth controllers on Qualcomm Snapdragon chipsets due to improper length validation when processing vendor-specific commands. Attackers could potenti...

CVE-2021-35083

HIGH CVSS 8.2 Jun 14, 2022

This vulnerability allows attackers to read memory beyond intended boundaries due to improper certificate chain validation in Qualcomm Snapdragon chipsets. It affects devices using vulnerable Snapdrag...

CVE-2021-35086

HIGH CVSS 7.5 Jun 14, 2022

This CVE describes a buffer over-read vulnerability in Qualcomm Snapdragon chipsets when processing NR system information messages. Attackers could potentially read sensitive data from adjacent memory...

CVE-2021-35094

HIGH CVSS 7.8 Jun 14, 2022

This vulnerability allows attackers to bypass authentication in Qualcomm Snapdragon chipsets by exploiting improper timeout-based verification in identity credential handling. It affects devices using...

CVE-2021-35096

HIGH CVSS 7.5 Jun 14, 2022

This vulnerability in Qualcomm Snapdragon chipsets involves improper memory allocation during counter check DLM handling, which can cause denial of service. It affects devices using Snapdragon Auto, C...

CVE-2021-35100

HIGH CVSS 7.5 Jun 14, 2022

This vulnerability is a buffer over-read in Qualcomm Snapdragon chipsets when parsing ID3 tags in media files. It allows attackers to read memory beyond allocated buffers, potentially exposing sensiti...

CVE-2021-35102

HIGH CVSS 7.8 Jun 14, 2022

This vulnerability is a buffer overflow in Qualcomm Snapdragon chipsets that could allow attackers to execute arbitrary code or cause denial of service. It affects devices using Snapdragon Auto, Compu...

CVE-2021-30350

HIGH CVSS 8.4 Jun 14, 2022

This vulnerability in Qualcomm Snapdragon chipsets allows memory corruption due to insufficient validation of MBN header size against input buffer. Attackers could potentially execute arbitrary code o...

CVE-2021-35076

HIGH CVSS 7.5 Jun 14, 2022

This vulnerability allows attackers to cause denial of service or potentially execute arbitrary code by sending a specially crafted RRC connection reconfiguration message to affected Qualcomm Snapdrag...

CVE-2021-30334

HIGH CVSS 8.4 Jun 14, 2022

This CVE describes a use-after-free vulnerability in Qualcomm Snapdragon chipsets where DRM file status isn't properly checked after file structure is freed. This could allow attackers to execute arbi...

CVE-2021-30281

HIGH CVSS 8.4 Jun 14, 2022

This vulnerability allows unauthorized access to secure memory space in Qualcomm Snapdragon chipsets due to improper access control checks during device configuration flashing. It affects multiple Sna...

CVE-2021-1950

HIGH CVSS 7.8 Apr 1, 2022

This vulnerability allows authenticated users to bypass face authentication on affected Qualcomm Snapdragon devices due to improper secure memory cleaning between user sessions. It affects multiple Sn...

CVE-2021-30329

HIGH CVSS 7.5 Apr 1, 2022

This vulnerability in Qualcomm Snapdragon chipsets allows attackers to trigger an assertion failure due to improper validation of TCI configuration. It affects automotive, compute, connectivity, indus...

CVE-2021-30332

HIGH CVSS 7.5 Apr 1, 2022

This vulnerability in Qualcomm Snapdragon chipsets allows attackers to trigger a denial-of-service condition via improper validation of Over-The-Air (OTA) configuration data. It affects devices using ...

CVE-2021-35088

HIGH CVSS 8.2 Apr 1, 2022

This vulnerability allows attackers to read memory beyond intended boundaries during Wi-Fi SSID information element parsing when using DFS channels on affected Qualcomm Snapdragon chipsets. Successful...

CVE-2021-35103

HIGH CVSS 7.8 Apr 1, 2022

This vulnerability allows an attacker to write data beyond allocated memory bounds in Qualcomm Snapdragon chipsets due to improper validation of timer values from firmware. It affects multiple Snapdra...

CVE-2021-35106

HIGH CVSS 7.8 Apr 1, 2022

This vulnerability allows attackers to read memory beyond intended boundaries in Qualcomm Snapdragon chipsets due to improper WMI message length calculation. It affects numerous Snapdragon-powered dev...