Cologne Firmware

Vendor:

First CVE: Jan 7, 2026 · Active for under a year

41
Total CVEs
More Total CVEs than 98% of tracked products
41.0
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 52% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Cologne Firmware over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 7, 2026
6 months ago
Most Recent CVE
Jul 6, 2026
21 days ago

CVE Severity & Scoring

Cologne Firmware41 CVEs
All CVEs352,785 CVEs
MediumHigh
Attack Vector
Local31 (75.6%)
Network4 (9.8%)
Unknown0 (0.0%)
Physical5 (12.2%)
Adjacent Network1 (2.4%)
Attack Complexity
Low39 (95.1%)
High2 (4.9%)
Unknown0 (0.0%)
User Interaction
None39 (95.1%)
Unknown0 (0.0%)
Required2 (4.9%)
Privileges Required
Low27 (65.9%)
High11 (26.8%)
None3 (7.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (41 CVEs).

41 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications.
Jun 1, 20267.833NONO
Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.
Jun 1, 20267.833NONO
Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use.
Jul 6, 20267.832NONO
Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.
Jul 6, 20267.832NONO
Memory corruption while processing multiple IOCTL command for escape operations.
Jun 1, 20267.832NONO
Memory corruption while processing IOCTL calls for escape operations.
Jun 1, 20267.832NONO
Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization.
Jun 1, 20267.832NONO
Memory corruption while processing fastboot OEM commands.
Jun 1, 20267.229NONO
Memory corruption while processing IOCTL command when device is in power-save state.
May 4, 20267.828NONO
Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
May 4, 20267.528NONO

Exploit Exposure

Signals from CVEs in this product scope (41 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (41 CVEs).

Media Mentions

Signals from CVEs in this product scope (41 CVEs).

Top CNAs Publishing CVEs For Cologne Firmware

Top CWEs

Versions

No cataloged versions.