CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

qualcomm

qcn5121_firmware

80 known vulnerabilities · sorted by CVSS score

CVE-2020-11134
CRITICAL9.8

Possible stack out of bound write might happen due to time bitmap length and bit duration fields of the attributes like NAN ranging setup attribute inside a NAN management frame are not Properly validated in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

qualcomm / aqt1000_firmware+324
Network
Published Jun 9, 2021
Page 1 of 4
CVE-2021-1972
CRITICAL9.8

Possible buffer overflow due to improper validation of device types during P2P search in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

qualcomm / apq8009_firmware+276
Network
Published Sep 8, 2021
CVE-2021-1965
CRITICAL9.8

Possible buffer overflow due to lack of parameter length check during MBSSID scan IE parse in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking

qualcomm / aqt1000_firmware+125
Network
Published Jul 13, 2021
CVE-2021-1976
CRITICAL9.8

A use after free can occur due to improper validation of P2P device address in PD Request frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

qualcomm / apq8009_firmware+246
Network
Published Sep 17, 2021
CVE-2023-33030
CRITICAL9.3

Memory corruption in HLOS while running playready use-case.

qualcomm / 315_5g_iot_modem_firmware+300
Local
Published Jan 2, 2024
CVE-2021-30275
CRITICAL9.3

Possible integer overflow in page alignment interface due to lack of address and size validation before alignment in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

qualcomm / ar8031_firmware+126
Local
Published Jan 3, 2022
CVE-2023-33032
CRITICAL9.3

Memory corruption in TZ Secure OS while requesting a memory allocation from TA region.

qualcomm / 9205_lte_modem_firmware+119
Local
Published Jan 2, 2024
CVE-2020-11126
CRITICAL9.1

Possible out of bound read while WLAN frame parsing due to lack of check for body and header length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

qualcomm / apq8096au_firmware+390
Network
Published Jun 9, 2021
CVE-2020-11275
CRITICAL9.1

Possible buffer over-read while parsing quiet IE in Rx beacon frame due to improper check of IE length in received beacon in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

qualcomm / apq8009_firmware+472
Network
Published Feb 22, 2021
CVE-2020-11276
CRITICAL9.1

Possible buffer over read while processing P2P IE and NOA attribute of beacon and probe response frames due to improper validation of P2P IE and NOA attribute lengths in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

qualcomm / apq8009_firmware+514
Network
Published Feb 22, 2021
CVE-2020-11301
CRITICAL9.1

Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

qualcomm / apq8009_firmware+268
Network
Published Sep 8, 2021
CVE-2020-11159
CRITICAL9.1

Buffer over-read can happen while processing WPA,RSN IE of beacon and response frames if IE length is less than length of frame pointer being accessed in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

qualcomm / apq8009_firmware+502
Network
Published Jun 9, 2021
CVE-2021-1924
CRITICAL9.0

Information disclosure through timing and power side-channels during mod exponentiation for RSA-CRT in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

qualcomm / apq8009_firmware+316
Local
Published Nov 12, 2021
CVE-2022-25652
CRITICAL9.0

Cryptographic issues in BSP due to improper hash verification in Snapdragon Wired Infrastructure and Networking

qualcomm / csr8811_firmware+59
Local
Published Sep 16, 2022
CVE-2021-30260
HIGH8.4

Possible Integer overflow to buffer overflow issue can occur due to improper validation of input parameters when extscan hostlist configuration command is received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

qualcomm / apq8009_firmware+257
Local
Published Sep 17, 2021
CVE-2021-30274
HIGH8.4

Possible integer overflow in access control initialization interface due to lack and size and address validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

qualcomm / ar8031_firmware+125
Local
Published Jan 3, 2022
CVE-2023-24852
HIGH8.4

Memory Corruption in Core due to secure memory access by user while loading modem image.

qualcomm / 315_5g_iot_modem_firmware+273
Local
Published Nov 7, 2023
CVE-2023-21628
HIGH8.4

Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command.

qualcomm / apq8017_firmware+282
Local
Published Jun 6, 2023
CVE-2021-30282
HIGH8.4

Possible out of bound write in RAM partition table due to improper validation on number of partitions provided in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

qualcomm / ar8031_firmware+124
Local
Published Jan 3, 2022
CVE-2020-11267
HIGH8.4

Stack out-of-bounds write occurs while setting up a cipher device if the provided IV length exceeds the max limit value in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

qualcomm / apq8009_firmware+270
Local
Published Jun 9, 2021