Qca6428 Firmware

Vendor:

First CVE: Jan 21, 2021 · Active for 5 years

104
Total CVEs
More Total CVEs than 99% of tracked products
17.3
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 64% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Qca6428 Firmware over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 21, 2021
5 years ago
Most Recent CVE
Jan 7, 2026
202 days ago

CVE Severity & Scoring

Qca6428 Firmware104 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local49 (47.1%)
Network51 (49.0%)
Unknown0 (0.0%)
Physical1 (1.0%)
Adjacent Network3 (2.9%)
Attack Complexity
Low103 (99.0%)
High1 (1.0%)
Unknown0 (0.0%)
User Interaction
None104 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low44 (42.3%)
High5 (4.8%)
None55 (52.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (104 CVEs).

104 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An out of bound memory access can occur due to improper validation of number of frames being passed during music playback in Snapdragon Auto, Snapdragon Compute, Snapdragon Connect
Jan 3, 20229.832NONO
Memory corruption in WLAN due to integer overflow to buffer overflow while parsing GTK frames. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer
Oct 19, 20229.830NONO
Possible buffer over read due to lack of length check while parsing beacon IE response in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electron
Oct 20, 20219.130NONO
A use after free can occur due to improper validation of P2P device address in PD Request frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer
Sep 17, 20219.830NONO
Possible buffer overflow due to improper validation of device types during P2P search in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snap
Sep 8, 20219.830NONO
Memory corruption while redirecting log file to any file location with any file name.
Apr 1, 20249.829NONO
Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connect
Sep 8, 20217.529NONO
Possible buffer overflow due to improper parsing of headers while playing the FLAC audio clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer I
Jun 14, 20229.828NONO
Possible out of bound read due to improper validation of IE length during SSID IE parse when channel is DFS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdra
Apr 1, 20229.128NONO
Possible buffer over-read while parsing quiet IE in Rx beacon frame due to improper check of IE length in received beacon in Snapdragon Auto, Snapdragon Compute, Snapdragon Connect
Feb 22, 20219.127NONO

Exploit Exposure

Signals from CVEs in this product scope (104 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (104 CVEs).

Media Mentions

Signals from CVEs in this product scope (104 CVEs).

Top CNAs Publishing CVEs For Qca6428 Firmware

Top CWEs

Versions

No cataloged versions.