205 Mobile Platform Firmware
Vendor:
First CVE: Jul 1, 2024 · Active for 2 years
15
Total CVEs
More Total CVEs than 93% of tracked products
7.5
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 64% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact 205 Mobile Platform Firmware over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 1, 2024
2 years ago
Most Recent CVE
Sep 24, 2025
307 days ago
CVE Severity & Scoring
205 Mobile Platform Firmware15 CVEs
13%
87%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local7 (46.7%)
Network8 (53.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low8 (53.3%)
High0 (0.0%)
None7 (46.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-21487HIGH Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length. | Sep 24, 2025 | 8.2 | 27 | NO | NO |
CVE-2024-23359HIGH Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network. | Sep 2, 2024 | 8.2 | 26 | NO | NO |
CVE-2024-23373HIGH Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released. | Jul 1, 2024 | 7.8 | 24 | NO | NO |
CVE-2024-53020HIGH Information disclosure may occur while decoding the RTP packet with invalid header extension from network. | Jun 3, 2025 | 8.2 | 23 | NO | NO |
CVE-2024-33027HIGH Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table. | Aug 5, 2024 | 7.8 | 23 | NO | NO |
CVE-2024-53026HIGH Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call. | Jun 3, 2025 | 8.2 | 22 | NO | NO |
CVE-2024-53021HIGH Information disclosure may occur while processing goodbye RTCP packet from network. | Jun 3, 2025 | 8.2 | 22 | NO | NO |
CVE-2024-43052HIGH Memory corruption while processing API calls to NPU with invalid input. | Dec 2, 2024 | 7.8 | 22 | NO | NO |
CVE-2024-38423HIGH Memory corruption while processing GPU page table switch. | Nov 4, 2024 | 7.8 | 22 | NO | NO |
CVE-2024-38422HIGH Memory corruption while processing voice packet with arbitrary data received from ADSP. | Nov 4, 2024 | 7.8 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (15 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (15 CVEs).
Media Mentions
Signals from CVEs in this product scope (15 CVEs).
Top CNAs Publishing CVEs For 205 Mobile Platform Firmware
Top CWEs
Versions
No cataloged versions.