Qca9985 Firmware
Vendor:
First CVE: Feb 22, 2021 · Active for 5 years
115
Total CVEs
More Total CVEs than 99% of tracked products
19.2
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 63% of tracked products
0.9%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Qca9985 Firmware over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 22, 2021
5 years ago
Most Recent CVE
Jun 1, 2026
57 days ago
CVE Severity & Scoring
Qca9985 Firmware115 CVEs
17%
72%
10%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local56 (48.7%)
Network53 (46.1%)
Unknown0 (0.0%)
Physical1 (0.9%)
Adjacent Network5 (4.3%)
Attack Complexity
Low114 (99.1%)
High1 (0.9%)
Unknown0 (0.0%)
User Interaction
None113 (98.3%)
Unknown0 (0.0%)
Required2 (1.7%)
Privileges Required
Low47 (40.9%)
High7 (6.1%)
None61 (53.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (115 CVEs).
115 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-33063HIGH Memory corruption in DSP Services during a remote call from HLOS to DSP. | Dec 5, 2023 | 7.8 | 64 | YES | NO |
CVE-2026-24088HIGH Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader. | Jun 1, 2026 | 8.2 | 34 | NO | NO |
CVE-2021-30351CRITICAL An out of bound memory access can occur due to improper validation of number of frames being passed during music playback in Snapdragon Auto, Snapdragon Compute, Snapdragon Connect | Jan 3, 2022 | 9.8 | 32 | NO | NO |
CVE-2021-1965CRITICAL Possible buffer overflow due to lack of parameter length check during MBSSID scan IE parse in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile, Snapd | Jul 13, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-1980CRITICAL Possible buffer over read due to lack of length check while parsing beacon IE response in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electron | Oct 20, 2021 | 9.1 | 30 | NO | NO |
CVE-2021-1976CRITICAL A use after free can occur due to improper validation of P2P device address in PD Request frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer | Sep 17, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-1972CRITICAL Possible buffer overflow due to improper validation of device types during P2P search in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snap | Sep 8, 2021 | 9.8 | 30 | NO | NO |
CVE-2024-21473CRITICAL Memory corruption while redirecting log file to any file location with any file name. | Apr 1, 2024 | 9.8 | 29 | NO | NO |
CVE-2023-33083CRITICAL Memory corruption in WLAN Host while processing RRM beacon on the AP. | Dec 5, 2023 | 9.8 | 29 | NO | NO |
CVE-2022-40514CRITICAL Memory corruption due to buffer copy without checking the size of input in WLAN Firmware while processing CCKM IE in reassoc response frame. | Feb 12, 2023 | 9.8 | 29 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (115 CVEs).
CISA KEV
1 CVE
0.9% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (115 CVEs).
Media Mentions
Signals from CVEs in this product scope (115 CVEs).
Top CNAs Publishing CVEs For Qca9985 Firmware
Top CWEs
Versions
No cataloged versions.